Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4vr-p2v7-rh48

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

EPSS

Процентиль: 68%
0.00558
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 3 лет назад

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

EPSS

Процентиль: 68%
0.00558
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79