Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-545q-9j8x-q2gf

Опубликовано: 20 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

EPSS

Процентиль: 83%
0.01959
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

CVSS3: 5.4
fstec
больше 2 лет назад

Уязвимость компонента Custom Logo («Пользовательский логотип») инструмента для мониторинга Nagios XI, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 83%
0.01959
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79