Логотип exploitDog
bind:CVE-2021-32245
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32245

Количество 2

Количество 2

nvd логотип

CVE-2021-32245

больше 4 лет назад

In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" that will point to http://localhost/pagekit/storage/exp.svg. When a user comes along to click that link, it will trigger a XSS attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mrwr-2945-fr22

больше 4 лет назад

Cross-site scripting in PageKit

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-32245

In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" that will point to http://localhost/pagekit/storage/exp.svg. When a user comes along to click that link, it will trigger a XSS attack.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-mrwr-2945-fr22

Cross-site scripting in PageKit

CVSS3: 5.4
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу