Stored XSS Vulnerability in File Name of the File Upload function
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.5epss 0.4%
probabilidad de explotación
0.4%top 64% de las CVE
explotación observada
noninguna fuente lo reporta
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:L
Productos afectados
Crafter Software · Crafter CMS