Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h46g-35r6-chx9

Опубликовано: 13 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

Download of Code Without Integrity Check vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.

Download of Code Without Integrity Check vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.

EPSS

Процентиль: 22%
0.00073
Низкий

8.4 High

CVSS3

Дефекты

CWE-434
CWE-494

Связанные уязвимости

CVSS3: 8.4
nvd
9 месяцев назад

The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.

EPSS

Процентиль: 22%
0.00073
Низкий

8.4 High

CVSS3

Дефекты

CWE-434
CWE-494