VvvebJs <= 2.0.5 - Cross-Site Scripting
Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.
vvvebjsPoC 已收录
CVSS—