Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 3.3%
from disclosure to weapon63 days
Published on NVDMar 15
1st PoC+63d
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.
CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
star7th · star7th/showdocpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/50941unverifiedcve_referencepacketstormsecurity.com/files/167198/Showdoc-2.10.3-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.