Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hh3-3gxg-jq86

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-74