Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wr4-2chq-phgj

Опубликовано: 12 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 5.9

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack.

This issue affects ALM Octane Management: from 16.2.100 through 24.4.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack.

This issue affects ALM Octane Management: from 16.2.100 through 24.4.

EPSS

Процентиль: 59%
0.00384
Низкий

8.6 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

nvd
около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octane Management: from 16.2.100 through 24.4.

EPSS

Процентиль: 59%
0.00384
Низкий

8.6 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-79