Количество 2
Количество 2
CVE-2022-32172
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
GHSA-7j6x-42mm-p7jm
Zinc Cross-site Scripting vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-32172 In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials. | 0% Низкий | больше 3 лет назад | ||
GHSA-7j6x-42mm-p7jm Zinc Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу