Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28h3-55jv-gc4g

Опубликовано: 22 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.2

Описание

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.

EPSS

Процентиль: 38%
0.0016
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.2
nvd
10 месяцев назад

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.

EPSS

Процентиль: 38%
0.0016
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-79