Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xgw-mp56-cmcq

Опубликовано: 14 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79