Логотип exploitDog
bind:CVE-2019-13644
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-13644

Количество 2

Количество 2

nvd логотип

CVE-2019-13644

больше 6 лет назад

Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9xmx-rj7j-fv9q

больше 3 лет назад

Firefly III vulnerable to stored XSS

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-13644

Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
github логотип
GHSA-9xmx-rj7j-fv9q

Firefly III vulnerable to stored XSS

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу