Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qcf-755r-4vhw

Опубликовано: 25 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.

EPSS

Процентиль: 28%
0.001
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1022

Связанные уязвимости

CVSS3: 6.1
nvd
около 1 года назад

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.

EPSS

Процентиль: 28%
0.001
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1022