Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmg5-r3c4-3fm9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Withdrawn Advisory: Fat Free CRM Cross-site Scripting vulnerability

Withdrawn

This advisory has been withdrawn because the CVE has been disputed and the underlying vulnerability is likely invalid. This link is maintained to preserve external references.

According to maintainers of Fat Free CRM, the CRM comment feature allows certain HTML markup, but santizes the output when rendered to page. This allows safe tags (such as <h1> which the author tested and reported as a vulnerability) but correctly disallows <script> tags and other dangerous entities.

Original Description

HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.

Пакеты

Наименование

fat_free_crm

rubygems
Затронутые версииВерсия исправления

<= 0.19.0

Отсутствует

EPSS

Процентиль: 82%
0.01758
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 6 лет назад

HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.

EPSS

Процентиль: 82%
0.01758
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79