Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6fj-c8gc-64v6

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

EPSS

Процентиль: 49%
0.00257
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

EPSS

Процентиль: 49%
0.00257
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79