Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7pfc-cc9x-8p4m

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Apache Isis Cross-site Scripting vulnerability

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.

Пакеты

Наименование

org.apache.isis.core:isis-core

maven
Затронутые версииВерсия исправления

< 2.0.0-M9

2.0.0-M9

EPSS

Процентиль: 96%
0.2198
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.

EPSS

Процентиль: 96%
0.2198
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79