ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 71% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims' browsers under the application origin.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
MacWarrior · clipbucket-v5PoCs públicas encontradas — 1
cve_referencehackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/MacWarrior/clipbucket-v5https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/functions.phphttps://github.com/MacWarrior/clipbucket-v5/commit/032f46937e091e22afa6c99f2c888575cc94e44bhttps://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182https://hackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-reflected-xss-via-query-parameters