Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9whv-vchq-g94v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

EPSS

Процентиль: 69%
0.00615
Низкий

8.8 High

CVSS3

Дефекты

CWE-1286
CWE-20
CWE-74

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

EPSS

Процентиль: 69%
0.00615
Низкий

8.8 High

CVSS3

Дефекты

CWE-1286
CWE-20
CWE-74