Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-236f-m6gm-vp93

Опубликовано: 18 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

EPSS

Процентиль: 14%
0.00046
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
9 месяцев назад

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

EPSS

Процентиль: 14%
0.00046
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79