PT-2018-16176 · Sexstatic · Sexstatic

·

CVE-2018-3755

·

Publicado

2018-06-01

·

Atualizado

2023-02-28

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions sexstatic versions 0.6.2 and earlier sexstatic (all versions)
Description The issue allows for stored cross-site scripting (XSS) if an attacker can control a filename served by the software. This can lead to HTML injection in directory names, resulting in Stored XSS when a malicious file is embedded with an iframe element used in the directory name.
Recommendations For sexstatic versions 0.6.2 and earlier, there is no information about a newer version that contains a fix for this issue. For sexstatic (all versions), do not install or use this module at this time, as there is currently no fix available for this issue.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3755
GHSA-QFH2-6F7Q-GR86

Produtos afetados

Sexstatic