Логотип exploitDog
bind:CVE-2025-56236
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-56236

Количество 2

Количество 2

nvd логотип

CVE-2025-56236

5 месяцев назад

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4fxf-xgrm-8fcj

5 месяцев назад

FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-56236

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-4fxf-xgrm-8fcj

FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability

0%
Низкий
5 месяцев назад

Уязвимостей на страницу