Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c348-367f-c282

Опубликовано: 20 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages

is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. A remote authenticated attacker could exploit this vulnerability using HTML tags in a text field of an object to inject malicious script into an email which would be executed in a victim's mail client within the security context of the OpenPages mail message. An attacker could use this for phishing or identity theft attacks.

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages

is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. A remote authenticated attacker could exploit this vulnerability using HTML tags in a text field of an object to inject malicious script into an email which would be executed in a victim's mail client within the security context of the OpenPages mail message. An attacker could use this for phishing or identity theft attacks.

EPSS

Процентиль: 21%
0.00066
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 5.4
nvd
12 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. A remote authenticated attacker could exploit this vulnerability using HTML tags in a text field of an object to inject malicious script into an email which would be executed in a victim's mail client within the security context of the OpenPages mail message. An attacker could use this for phishing or identity theft attacks.

CVSS3: 5.4
fstec
12 месяцев назад

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю выполнить произвольный HTML-код

EPSS

Процентиль: 21%
0.00066
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-80