Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-532f-v327-35gw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.

EPSS

Процентиль: 50%
0.00268
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.

EPSS

Процентиль: 50%
0.00268
Низкий

Дефекты

CWE-79