Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cm8-rv8m-x9gf

Опубликовано: 03 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

EPSS

Процентиль: 74%
0.00809
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

EPSS

Процентиль: 74%
0.00809
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79