Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3c93-hfq2-f4vp

Опубликовано: 26 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host.

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host.

EPSS

Процентиль: 60%
0.00405
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.7
nvd
около 3 лет назад

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host.

EPSS

Процентиль: 60%
0.00405
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20