Lucene search

K
osvGoogleOSV:GHSA-QFH2-6F7Q-GR86
HistoryOct 01, 2018 - 4:30 p.m.

Cross-Site Scripting in sexstatic

2018-10-0116:30:38
Google
osv.dev
8

0.001 Low

EPSS

Percentile

38.0%

All versions of sexstatic are vulnerable to stored cross-site scripting (xss). This is exploitable if an attacker can control a filename that is served by sexstatic.

Recommendation

As there is no fix is currently available for this vulnerability it is our recommendation to not install or used this module at this time.

CPENameOperatorVersion
sexstaticle0.6.2

0.001 Low

EPSS

Percentile

38.0%