Логотип exploitDog
bind:CVE-2018-18087
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-18087

Количество 2

Количество 2

nvd логотип

CVE-2018-18087

больше 7 лет назад

The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6wpq-76c5-9mpq

больше 3 лет назад

The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-18087

The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
github логотип
GHSA-6wpq-76c5-9mpq

The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу