Логотип exploitDog
bind:CVE-2026-22257
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22257

Количество 2

Количество 2

nvd логотип

CVE-2026-22257

12 дней назад

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-54m3-5fxr-2f3j

12 дней назад

Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22257

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.

CVSS3: 8.8
0%
Низкий
12 дней назад
github логотип
GHSA-54m3-5fxr-2f3j

Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names

CVSS3: 8.8
0%
Низкий
12 дней назад

Уязвимостей на страницу