Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4pm-v5gm-7f4h

Опубликовано: 12 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

EPSS

Процентиль: 56%
0.00343
Низкий

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
почти 2 года назад

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

EPSS

Процентиль: 56%
0.00343
Низкий

7.1 High

CVSS3

Дефекты

CWE-79