Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58rh-53vh-8w68

Опубликовано: 06 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 5.4

Описание

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.

We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.

We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later

EPSS

Процентиль: 77%
0.01037
Низкий

7 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later

CVSS3: 8.2
fstec
больше 1 года назад

Уязвимость приложения для загрузки файлов QTS Download Station операционных системы QTS сетевых устройств Qnap, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 77%
0.01037
Низкий

7 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79