Логотип exploitDog
bind:CVE-2019-19325
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-19325

Количество 2

Количество 2

nvd логотип

CVE-2019-19325

почти 6 лет назад

SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows performing XSS (Cross-Site Scripting) on some forms built with user input (Request data). This can lead to phishing attempts to obtain a user's credentials or other sensitive user input.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qvrv-2x7x-78x2

почти 6 лет назад

Reflected XSS in SilverStripe

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-19325

SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows performing XSS (Cross-Site Scripting) on some forms built with user input (Request data). This can lead to phishing attempts to obtain a user's credentials or other sensitive user input.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
github логотип
GHSA-qvrv-2x7x-78x2

Reflected XSS in SilverStripe

CVSS3: 6.1
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу