Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hj5-ppfx-65vf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.

Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.

EPSS

Процентиль: 75%
0.0088
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.

EPSS

Процентиль: 75%
0.0088
Низкий