Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wm4-f538-3x27

Опубликовано: 06 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.

EPSS

Процентиль: 19%
0.0006
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.

EPSS

Процентиль: 19%
0.0006
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79