CVE-2023-3445
LOW3.5EPSS 0.13%Spina Cross-site Scripting vulnerability
發布日:2023/6/28修改日:2024/2/16
描述
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.
受影響套件(1)
- RubyGems/spinafrom 0, < 2.15.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.5 | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-3445
- PATCHhttps://github.com/spinacms/spina
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/spina/CVE-2023-3445.yml
- WEBhttps://github.com/spinacms/spina/commit/9adfe7b4807b3cc10dbb7351a26cc32f5d8c14a3
- WEBhttps://huntr.dev/bounties/18a74a9d-4a2d-4bf8-ae62-56a909427070