Lucene search

K
osvGoogleOSV:GHSA-Q6V4-XJP2-8GGV
HistoryMay 13, 2022 - 1:11 a.m.

Securimage HTML Injection

2022-05-1301:11:18
Google
osv.dev
3
securimage
html injection
remote attackers
email message
$_server['http_user_agent']

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

57.2%

HTML Injection in Securimage prior to 3.6.6 allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

57.2%

Related for OSV:GHSA-Q6V4-XJP2-8GGV