Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hj7h-g298-7rxc

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

EPSS

Процентиль: 63%
0.00438
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

EPSS

Процентиль: 63%
0.00438
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79