Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qj4-8pgw-5j87

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.

Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.

EPSS

Процентиль: 50%
0.0027
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.

EPSS

Процентиль: 50%
0.0027
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79