Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wc4-gq9m-293h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

EPSS

Процентиль: 48%
0.00252
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

CVSS3: 8.2
nvd
больше 4 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

CVSS3: 8.2
debian
больше 4 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the ...

EPSS

Процентиль: 48%
0.00252
Низкий

Дефекты

CWE-79