Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g28-qxjm-5vh2

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

EPSS

Процентиль: 57%
0.0035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
redhat
больше 3 лет назад

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

CVSS3: 6.1
nvd
больше 3 лет назад

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость менеджера ovirt-engine средства управления виртуальной инфраструктурой Ovirt, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 57%
0.0035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79