Логотип exploitDog
bind:CVE-2018-1000062
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1000062

Количество 2

Количество 2

nvd логотип

CVE-2018-1000062

почти 8 лет назад

WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-m396-hjxc-mcjq

больше 3 лет назад

WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-1000062

WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.

CVSS3: 4.4
0%
Низкий
почти 8 лет назад
github логотип
GHSA-m396-hjxc-mcjq

WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу