Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv7m-wc3v-wr3w

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

SimpleSAMLphp XSS Vulnerability

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

Пакеты

Наименование

simplesamlphp/simplesamlphp

composer
Затронутые версииВерсия исправления

>= 1.12.0, < 1.14.16

1.14.16

EPSS

Процентиль: 57%
0.00355
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

CVSS3: 6.1
nvd
около 8 лет назад

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

CVSS3: 6.1
debian
около 8 лет назад

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable ...

EPSS

Процентиль: 57%
0.00355
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79