Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rw2-3hhp-rc46

Опубликовано: 21 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.6

Описание

Cross-site Scripting Vulnerability in Statement Browser

Impact

A maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser.

Patches

The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS.

Workarounds

No workarounds exist, we recommend upgrading to version 1.2.17 of the library or version 0.7.5 of SQL LRS immediately.

References

Пакеты

Наименование

com.yetanalytics:lrs

maven
Затронутые версииВерсия исправления

< 1.2.17

1.2.17

EPSS

Процентиль: 38%
0.00166
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
почти 2 года назад

com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.

EPSS

Процентиль: 38%
0.00166
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79