Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8g2f-8jp6-pr2w

Опубликовано: 25 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

EPSS

Процентиль: 94%
0.12402
Средний

9.8 Critical

CVSS3

Дефекты

CWE-113
CWE-74

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

EPSS

Процентиль: 94%
0.12402
Средний

9.8 Critical

CVSS3

Дефекты

CWE-113
CWE-74