Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-72218
HistoryMar 29, 2022 - 12:00 a.m.

DouPHP Cross-Site Scripting Vulnerability (CNVD-2022-72218)

2022-03-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
5

0.001 Low

EPSS

Percentile

23.0%

A cross-site scripting vulnerability exists in DouPHP, a lightweight enterprise content management system (CMS) from China DouShell Network Technology. The vulnerability stems from a lack of data validation filtering of user-supplied data and output in the upload function of dmin/show.php. An attacker could use this vulnerability to execute arbitrary Web script or HTML via a crafted image file.

0.001 Low

EPSS

Percentile

23.0%

Related for CNVD-2022-72218