Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4778-fgpq-p5vc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79