Логотип exploitDog
bind:CVE-2020-12707
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-12707

Количество 2

Количество 2

nvd логотип

CVE-2020-12707

почти 6 лет назад

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-x28g-jx38-xw6g

больше 3 лет назад

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-12707

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
github логотип
GHSA-x28g-jx38-xw6g

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу