Логотип exploitDog
bind:CVE-2020-19887
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-19887

Количество 2

Количество 2

nvd логотип

CVE-2020-19887

больше 5 лет назад

DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-vgjp-xxm4-jrxg

больше 3 лет назад

DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-19887

DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-vgjp-xxm4-jrxg

DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу