Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96xr-jq73-gwf6

Опубликовано: 05 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's browser.

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's browser.

EPSS

Процентиль: 33%
0.00133
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's browser.

EPSS

Процентиль: 33%
0.00133
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79