Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c8q-55w7-h67h

Опубликовано: 10 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

An authenticated attacker is able to create alerts that trigger a stored XSS attack. 

An authenticated attacker is able to create alerts that trigger a stored XSS attack. 

EPSS

Процентиль: 31%
0.00117
Низкий

8.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.7
nvd
больше 2 лет назад

An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * click add * click apply * create a test alert * The test alert will run the command “id | tee /tmp/ttttttddddssss” as root. * after the test alert inspect /tmp/ttttttddddssss it'll contain the ids of the root user.

EPSS

Процентиль: 31%
0.00117
Низкий

8.7 High

CVSS3

Дефекты

CWE-79