Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg9g-9mr2-cpv6

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

EPSS

Процентиль: 6%
0.00166
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 5.4
nvd
10 месяцев назад

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVSS3: 5.4
fstec
10 месяцев назад

Уязвимость платформы управления рисками на предприятии IBM OpenPages, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный HTML-код

EPSS

Процентиль: 6%
0.00166
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80