Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr2w-874h-3jjj

Опубликовано: 29 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

EPSS

Процентиль: 50%
0.00271
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
nvd
больше 3 лет назад

If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

EPSS

Процентиль: 50%
0.00271
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601