Количество 2
Количество 2
CVE-2018-20583
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt).
GHSA-qx76-c53f-5c7q
PHP League CommonMark vulnerable to Cross-Site Scripting (XSS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-20583 Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt). | CVSS3: 6.1 | 0% Низкий | около 7 лет назад | |
GHSA-qx76-c53f-5c7q PHP League CommonMark vulnerable to Cross-Site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу