Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-25715

Опубликовано: 28 мая 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dogtag-pkifixed11.0.0-1package
dogtag-pkino-dsabullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1891016

  • https://github.com/dogtagpki/pki/commit/13f4c7fe7d71d42b46b25f3e8472ef7f35da5dd6

EPSS

Процентиль: 57%
0.00356
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 4 лет назад

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

CVSS3: 5.9
redhat
больше 4 лет назад

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

CVSS3: 6.1
nvd
около 4 лет назад

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

github
около 3 лет назад

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

oracle-oval
больше 4 лет назад

ELSA-2021-0851: pki-core security and bug fix update (IMPORTANT)

EPSS

Процентиль: 57%
0.00356
Низкий