Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8363-pjm5-wqcw

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

EPSS

Процентиль: 55%
0.00321
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
почти 7 лет назад

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

EPSS

Процентиль: 55%
0.00321
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79