Vulnerability Details CVE-2018-11351
script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the shared files description file and allow the execution of a JavaScript payload each time an administrator searches or lists uploaded files. These two injections could be triggered without authentication, and target the administrator. The attack vectors are the Content-Type field and the filename parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-11351
-
cpe:2.3:a:jirafeau:jirafeau:1.0
-
cpe:2.3:a:jirafeau:jirafeau:1.1
-
cpe:2.3:a:jirafeau:jirafeau:1.2.0
-
cpe:2.3:a:jirafeau:jirafeau:2.0.0
-
cpe:2.3:a:jirafeau:jirafeau:3.0.0
-
cpe:2.3:a:jirafeau:jirafeau:3.1.0
-
cpe:2.3:a:jirafeau:jirafeau:3.2.0
-
cpe:2.3:a:jirafeau:jirafeau:3.2.1
-
cpe:2.3:a:jirafeau:jirafeau:3.3.0
-
cpe:2.3:a:jirafeau:jirafeau:3.4.0