Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45040
HistoryJan 13, 2024 - 7:37 p.m.

Cross Site Scripting(XSS)

2024-01-1319:37:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
cross site scripting
spip:sid
vulnerability
input validation
attacker
ecrire/public/assembler.php
software

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

20.6%

spip:sid is vulnerable to Cross Site Scripting(XSS). This vulnerability due to input from_request() is not restricted to safe characters. It allow an attacker to change files in ecrire/public/assembler.php

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

20.6%