Source |
CVE Liste |
Identifiant |
8302675 |
Date de publication |
2023-01-19 19:15:10 (vue: 2023-01-19 22:08:55) |
Titre |
CVE-2022-46888 |
Texte |
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php. |
Notes |
|
Envoyé |
Oui |
Condensat |
/log /login /moresmiles /user /viewrequests 2022 46888 allow arbitrary attackers ban before cross cve html inject log multiple myhr nexusphp parameter php php; query reflective remote script scripting secret site text vulnerabilities web xss |
Tags |
|
Stories |
|
Move |
|