Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cxw-p58p-m7w4

Опубликовано: 12 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

EPSS

Процентиль: 67%
0.00544
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

EPSS

Процентиль: 67%
0.00544
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79