The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade universal-omega/dynamic-page-list3
to version 3.6.4 or higher.
universal-omega/dynamic-page-list3 is a The DynamicPageList3 extension allows creating lists of other articles based on their category, namespace, title, references or template usage and include contents or arguments of template calls of those articles into your page.
Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor via the #dpl
parameters. An attacker can access hidden or suppressed usernames by crafting specific queries that exploit the exposure of sensitive user information.