Логотип exploitDog
bind:CVE-2023-32670
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32670

Количество 2

Количество 2

nvd логотип

CVE-2023-32670

больше 2 лет назад

Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-qxv7-7h44-6g5h

больше 2 лет назад

Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-32670

Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.

CVSS3: 9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qxv7-7h44-6g5h

Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.

CVSS3: 9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу