Количество 2
Количество 2
CVE-2018-3748
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.
GHSA-7375-vjr2-3g7w
Cross-Site Scripting in glance
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-3748 There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name. | CVSS3: 6.1 | 0% Низкий | больше 7 лет назад | |
GHSA-7375-vjr2-3g7w Cross-Site Scripting in glance | CVSS3: 6.1 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу