Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9f7-pmc4-vm2c

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

EPSS

Процентиль: 27%
0.00343
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
29 дней назад

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

EPSS

Процентиль: 27%
0.00343
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79