Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72cx-4fqp-fx62

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

EPSS

Процентиль: 43%
0.00209
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

CVSS3: 6.1
debian
больше 4 лет назад

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote a ...

EPSS

Процентиль: 43%
0.00209
Низкий

Дефекты

CWE-79