Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18323
HistorySep 18, 2021 - 12:00 a.m.

PeerTube Cross-Site Scripting Vulnerability

2021-09-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

32.9%

PeerTube is a decentralized video sharing service platform. Peertube has a cross-site scripting vulnerability in versions prior to v3.4.0, which stems from the application’s lack of user input data validation and filtering of the data at the input location, and could be used by an attacker to upload an SVG image and then send the url of the image to execute JavaScript on the client side. code on the client side.

CPENameOperatorVersion
peertube peertubelt3.4.0

0.001 Low

EPSS

Percentile

32.9%

Related for CNVD-2022-18323