← voltar
CVE-2017-20122

Bitrix Site Manager Contact Form cross site scripting

CVSS 3.5 LOWEPSS 0.5%CWE-80
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
30 jun 2022Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Produtos afetados
Bitrix · Site Manager

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →