Логотип exploitDog
bind:CVE-2022-25229
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25229

Количество 2

Количество 2

nvd логотип

CVE-2022-25229

больше 3 лет назад

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pfm3-fqrj-vmfw

больше 3 лет назад

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-25229

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pfm3-fqrj-vmfw

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу