Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37m8-vrcv-2x3f

Опубликовано: 25 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

EPSS

Процентиль: 15%
0.00048
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.4
nvd
10 месяцев назад

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

EPSS

Процентиль: 15%
0.00048
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79