1 results (0.022 seconds)

CVSS: 7.6EPSS: 0%CPEs: 1EXPL: 0

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clibo-manager • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •