Lucene search

K
osvGoogleOSV:GHSA-PWGG-R6FQ-MF94
HistoryMay 24, 2022 - 5:32 p.m.

YOURLS Stored Cross Site Scripting (XSS)

2022-05-2417:32:11
Google
osv.dev
4
yourls
stored cross site scripting
xss
admin panel
versions 1.5 - 1.7.10
authenticated user
php plugin
malicious payload

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

26.9%

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

26.9%

Related for OSV:GHSA-PWGG-R6FQ-MF94