Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c4j-jvmg-2xq2

Опубликовано: 21 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.

Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.

EPSS

Процентиль: 18%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.6
nvd
около 2 лет назад

Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.

EPSS

Процентиль: 18%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-79