Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58r8-9m4c-m7wh

Опубликовано: 02 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

EPSS

Процентиль: 36%
0.00149
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.9
nvd
больше 3 лет назад

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

EPSS

Процентиль: 36%
0.00149
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79