Логотип exploitDog
bind:CVE-2025-55135
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-55135

Количество 2

Количество 2

nvd логотип

CVE-2025-55135

6 месяцев назад

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-jcj4-g9w3-h34q

6 месяцев назад

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-55135

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-jcj4-g9w3-h34q

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

CVSS3: 6.4
0%
Низкий
6 месяцев назад

Уязвимостей на страницу