Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67q7-73hh-wrm4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

EPSS

Процентиль: 45%
0.00227
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
nvd
больше 6 лет назад

In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

EPSS

Процентиль: 45%
0.00227
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79