Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h9c-f287-c6vp

Опубликовано: 06 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Improper Control of Interaction Frequency in Apache syncope-core

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

Пакеты

Наименование

org.apache.syncope:syncope-core

maven
Затронутые версииВерсия исправления

< 2.0.11

2.0.11

Наименование

org.apache.syncope:syncope-core

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.2

2.1.2

EPSS

Процентиль: 77%
0.01003
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-799

Связанные уязвимости

CVSS3: 5.4
nvd
больше 7 лет назад

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

EPSS

Процентиль: 77%
0.01003
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-799