Логотип exploitDog
bind:CVE-2024-52702
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52702

Количество 2

Количество 2

nvd логотип

CVE-2024-52702

около 1 года назад

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hrg-xmqp-9q4v

около 1 года назад

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-52702

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.

CVSS3: 5.4
1%
Низкий
около 1 года назад
github логотип
GHSA-2hrg-xmqp-9q4v

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter.

CVSS3: 5.4
1%
Низкий
около 1 года назад

Уязвимостей на страницу