Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78cf-35f9-pxqf

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The ACEManager component of ALEOS 4.16 and earlier allows an

authenticated user with Administrator privileges to access a file

upload field which does not fully validate the file name, creating a

Stored Cross-Site Scripting condition.

The ACEManager component of ALEOS 4.16 and earlier allows an

authenticated user with Administrator privileges to access a file

upload field which does not fully validate the file name, creating a

Stored Cross-Site Scripting condition.

EPSS

Процентиль: 1%
0.0001
Низкий

8.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость компонента ACEManager операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 1%
0.0001
Низкий

8.1 High

CVSS3

Дефекты

CWE-79