Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx87-ccx6-jgpm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.

A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.

EPSS

Процентиль: 65%
0.00497
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.

EPSS

Процентиль: 65%
0.00497
Низкий

Дефекты

CWE-79