Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q53-9g7q-p5mg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.

Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.

EPSS

Процентиль: 51%
0.00275
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
почти 5 лет назад

Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.

EPSS

Процентиль: 51%
0.00275
Низкий

Дефекты

CWE-79