Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-72215
HistoryMar 31, 2022 - 12:00 a.m.

Dolphin PHP Cross-Site Scripting Vulnerability

2022-03-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
dolphinphp
cross-site scripting
thinkphp 5.1.34
data validation
client-side execution
security vulnerability

EPSS

0.001

Percentile

21.4%

DolphinPhp is a set of Php rapid development framework based on ThinkPhp 5.1.34 Lts. A cross-site scripting vulnerability exists in DolphinPHP 1.5.0 and prior versions, which stems from the program’s lack of data validation filtering of user-supplied and output data. An attacker could exploit the vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

21.4%

Related for CNVD-2022-72215