Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08450
HistoryJan 14, 2022 - 12:00 a.m.

Directus Cross-Site Scripting Vulnerability

2022-01-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
directus
cross-site scripting
vulnerability
media upload
javascript
low-privilege attackers

EPSS

0.001

Percentile

21.4%

Directus is a live Api and application dashboard. Used to manage Sql database content, Directus suffers from a cross-site scripting vulnerability that allows unrestricted uploading of .html files in the media upload function, which can be exploited by low-privilege attackers to execute JavaScript code on the client side.

EPSS

0.001

Percentile

21.4%

Related for CNVD-2022-08450