Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg9g-9mr2-cpv6

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

EPSS

Процентиль: 10%
0.00036
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVSS3: 5.4
fstec
3 месяца назад

Уязвимость платформы управления рисками на предприятии IBM OpenPages, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный HTML-код

EPSS

Процентиль: 10%
0.00036
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80