Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44rr-528q-8qhv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.

CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.

EPSS

Процентиль: 63%
0.00442
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 11 лет назад

CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.

EPSS

Процентиль: 63%
0.00442
Низкий

Дефекты

CWE-79