Количество 2
Количество 2
CVE-2018-7035
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.
GHSA-m2r2-qc49-gqw4
Gleez CMS Stored XSS
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-7035 Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action. | CVSS3: 5.4 | 0% Низкий | почти 8 лет назад | |
GHSA-m2r2-qc49-gqw4 Gleez CMS Stored XSS | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу