Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-82269
HistoryApr 05, 2022 - 12:00 a.m.

Totaljs Cross-Site Scripting Vulnerability (CNVD-2022-82269)

2022-04-0500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
totaljs
cross-site scripting
vulnerability
content management system
total avengers
slovakia
javascript-based
node applications

EPSS

0.001

Percentile

21.8%

Total Avengers Totaljs Framework is a Javascript-based code base for building web, desktop, service or IoT applications from Total Avengers, Slovakia. The application is similar to PHPs Laravel, Pythons Django, ASP.NET MVC for building Node applications.A cross-site scripting vulnerability exists in versions of Totaljs content management system prior to 2022-02-28. An attacker can exploit this vulnerability to execute arbitrary Web script or HTML by injecting a carefully crafted payload into the page name text field when creating a new page.

EPSS

0.001

Percentile

21.8%

Related for CNVD-2022-82269