Логотип exploitDog
bind:CVE-2022-32167
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-32167

Количество 2

Количество 2

nvd логотип

CVE-2022-32167

больше 3 лет назад

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fg25-gq9g-32mx

больше 3 лет назад

Cross site scripting in Cloudreve

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-32167

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fg25-gq9g-32mx

Cross site scripting in Cloudreve

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу