Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3632-grrp-f8wr

Опубликовано: 29 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

EPSS

Процентиль: 49%
0.00261
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

CVSS3: 5.5
nvd
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

CVSS3: 5.5
debian
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service ( ...

EPSS

Процентиль: 49%
0.00261
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-436