Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-77826
HistoryMay 18, 2022 - 12:00 a.m.

Total Avengers Totaljs Framework Cross-Site Scripting Vulnerability

2022-05-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
total avengers totaljs
framework
cross-site scripting
vulnerability
stored
pdf files
javascript

EPSS

0.001

Percentile

21.4%

Total Avengers Totaljs Framework is a Javascript-based code base for building web, desktop, service or IoT applications from Total Avengers, Slovakia. The application is similar to PHPs Laravel, Pythons Django, ASP.NET MVC for building Node applications.A cross-site scripting vulnerability exists in Total Avengers Totaljs Framework version 3.4.5, which stems from a stored cross-site scripting issue in the upload functionality. An attacker can execute arbitrary Web scripts via PDF files embedded with JavaScript.

EPSS

0.001

Percentile

21.4%

Related for CNVD-2022-77826