Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r7f-f866-24h2

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

EPSS

Процентиль: 66%
0.00516
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

EPSS

Процентиль: 66%
0.00516
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79