CVE-2021-44118

MEDIUM5.4EPSS 0.28%

spip - security update

發布日:2022/1/26修改日:2026/5/29
也稱為:DSA-5028-1DEBIAN-CVE-2021-44118DEBIAN-CVE-2021-44120DEBIAN-CVE-2021-44122DEBIAN-CVE-2021-44123

描述

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(1)