Логотип exploitDog
bind:CVE-2025-51487
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-51487

Количество 2

Количество 2

nvd логотип

CVE-2025-51487

6 месяцев назад

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a new Article.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-p632-58pp-c9xg

6 месяцев назад

moonshine Stored Cross-Site Scripting Vulnerability in Create Article

CVSS3: 4.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-51487

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a new Article.

CVSS3: 4.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-p632-58pp-c9xg

moonshine Stored Cross-Site Scripting Vulnerability in Create Article

CVSS3: 4.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу