Логотип exploitDog
bind:CVE-2020-9322
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-9322

Количество 2

Количество 2

nvd логотип

CVE-2020-9322

6 месяцев назад

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v2qm-4x3j-gc57

6 месяцев назад

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-9322

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-v2qm-4x3j-gc57

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

CVSS3: 8.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу