Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rrx-pphc-qfv9

Опубликовано: 03 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.

Пакеты

Наименование

pgadmin4

pip
Затронутые версииВерсия исправления

< 9.2

9.2

EPSS

Процентиль: 13%
0.00044
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.1
nvd
10 месяцев назад

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.

CVSS3: 9.1
debian
10 месяцев назад

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site ...

EPSS

Процентиль: 13%
0.00044
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-79