Логотип exploitDog
bind:CVE-2023-41710
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-41710

Количество 2

Количество 2

nvd логотип

CVE-2023-41710

около 2 лет назад

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9rm8-w7j5-j66w

около 2 лет назад

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-41710

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-9rm8-w7j5-j66w

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу