CVE-2024-50637
MEDIUM6.1EPSS 0.59%UnoPim Cross-site Scripting vulnerability
Published: 11/6/2024Modified: 11/6/2024
Also known as:GHSA-hv6m-qj65-26q3
Description
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies.
Affected packages (1)
- Packagist/unopim/unopimfrom 0, < 0.1.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |