Описание
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 3.1.4-4~deb9u5build0.18.04.1 |
| devel | not-affected | 4.0.1 |
| esm-apps/bionic | released | 3.1.4-4~deb9u5build0.18.04.1 |
| esm-apps/focal | released | 3.2.7-1ubuntu0.1 |
| esm-apps/jammy | not-affected | 4.0.1 |
| esm-apps/noble | not-affected | 4.0.1 |
| esm-apps/xenial | needed | |
| focal | released | 3.2.7-1ubuntu0.1 |
| impish | released | 3.2.11-3+deb11u3build0.21.10.1 |
| jammy | not-affected | 4.0.1 |
Показывать по
Ссылки на источники
3.5 Low
CVSS2
5.4 Medium
CVSS3
Связанные уязвимости
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. ...
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
3.5 Low
CVSS2
5.4 Medium
CVSS3