Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g84v-6fgf-jw3g

Опубликовано: 29 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

EPSS

Процентиль: 31%
0.00117
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.6
nvd
около 4 лет назад

SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

EPSS

Процентиль: 31%
0.00117
Низкий

Дефекты

CWE-79