
icecoder/ICEcoder
Releases74
Frequency1 month 2 weeks
Last Release
Stars1.42K
Browser code editor awesomeness
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 7.5 HIGH | — | ||
ICEcoder v8.1 allows attackers to execute a directory traversal. | |||
| 4.8 MEDIUM | 3.5 LOW | ||
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||
| 5.4 MEDIUM | 3.5 LOW | ||
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed. | |||