Cross-Site Scripting Vulnerability in JPress by Fuhai
CVE-2019-6278

5.4MEDIUM

Key Information:

Vendor

Jpress

Status
Vendor
CVE Published:
3 October 2022

What is CVE-2019-6278?

A cross-site scripting vulnerability was identified in JPress version 1.0.4, allowing attackers to exploit markdown input and execute arbitrary JavaScript code. This vulnerability occurs specifically when the code input option is utilized, which can compromise the integrity of the application and its users. To mitigate the risk, upgrading to the latest version and implementing input validation measures is crucial.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.