Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vmv-5g75-qpqc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

EPSS

Процентиль: 77%
0.01009
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
больше 5 лет назад

Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

EPSS

Процентиль: 77%
0.01009
Низкий

Дефекты

CWE-79