Логотип exploitDog
bind:CVE-2025-47204
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47204

Количество 2

Количество 2

nvd логотип

CVE-2025-47204

9 месяцев назад

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-gv5r-9gxr-v74w

9 месяцев назад

Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47204

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).

CVSS3: 6.1
1%
Низкий
9 месяцев назад
github логотип
GHSA-gv5r-9gxr-v74w

Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data

CVSS3: 6.1
1%
Низкий
9 месяцев назад

Уязвимостей на страницу