Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j95g-9p6g-8p25

Опубликовано: 04 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

EPSS

Процентиль: 70%
0.00652
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

EPSS

Процентиль: 70%
0.00652
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79