Lucene search

K
osvGoogleOSV:GHSA-58W4-W77W-QV3W
HistoryNov 16, 2020 - 9:23 p.m.

Reflected XSS with parameters in PostComment

2020-11-1621:23:29
Google
osv.dev
10
reflected xss
postcomment
attacker injection
malicious link
patch 4.2.0

EPSS

0.001

Percentile

29.3%

Impact

An attacker could inject malicious web code into the users’ web browsers by creating a malicious link.

Patches

The problem is fixed in 4.2.0

References

Cross-site Scripting (XSS) - Reflected (CWE-79)

EPSS

0.001

Percentile

29.3%

Related for OSV:GHSA-58W4-W77W-QV3W