Логотип exploitDog
bind:CVE-2022-37137
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-37137

Количество 2

Количество 2

nvd логотип

CVE-2022-37137

больше 3 лет назад

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43gg-3jq2-xwfh

больше 3 лет назад

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-37137

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43gg-3jq2-xwfh

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу