Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x5j-gwp5-7hgh

Опубликовано: 05 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.

EPSS

Процентиль: 36%
0.00149
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.

EPSS

Процентиль: 36%
0.00149
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79