Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8j5-7r4h-vj2g

Опубликовано: 13 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2
CVSS3: 3.5

Описание

DbGate has cross site scripting via the SVG Icon String Handler component

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component.

Пакеты

Наименование

dbgate-web

npm
Затронутые версииВерсия исправления

< 7.1.5

7.1.5

EPSS

Процентиль: 9%
0.00191
Низкий

2 Low

CVSS4

3.5 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
4 месяца назад

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component.

EPSS

Процентиль: 9%
0.00191
Низкий

2 Low

CVSS4

3.5 Low

CVSS3

Дефекты

CWE-79