Loading HuntDB...

GHSA-wh3q-8jwf-qv4m

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/admin/index.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

Related CVEs

Key Information

GHSA ID
GHSA-wh3q-8jwf-qv4m
Published
March 18, 2024 3:30 PM
Last Modified
April 17, 2025 9:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.