Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr5m-r6hv-j389

Опубликовано: 09 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

3DSecure 2.0 allows reflected XSS in the 3DS Authorization Challenge via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.

3DSecure 2.0 allows reflected XSS in the 3DS Authorization Challenge via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

5.4 Medium

CVSS3

Дефекты

CWE-79