Логотип exploitDog
bind:CVE-2020-15156
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15156

Количество 2

Количество 2

nvd логотип

CVE-2020-15156

больше 5 лет назад

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43m5-c88r-cjvv

больше 5 лет назад

XSS due to lack of CSRF validation for replying/publishing

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15156

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

CVSS3: 6.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-43m5-c88r-cjvv

XSS due to lack of CSRF validation for replying/publishing

CVSS3: 6.8
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу