Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jacopo Talamini

Pesquisador deYarix
#47228de 53,639
5.4CVSS total
Vulnerabilidades · 1
PT-2023-22510
5.4
2023-07-07
Unknown · Gis3W G3W-Suite · CVE-2023-29998
**Name of the Vulnerable Software and Affected Versions** Gis3W g3w-suite version 3.5 **Description** A Cross-site scripting (XSS) vulnerability in the content editor allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the `description` parameter. **Recommendations** For Gis3W g3w-suite version 3.5, consider restricting access to the content editor to minimize the risk of exploitation until a patch is available. Avoid using the `description` parameter in the affected content editor until the issue is resolved.