Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv4p-6m84-hhpv

Опубликовано: 28 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

EPSS

Процентиль: 37%
0.00158
Низкий

8.1 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.1
nvd
12 месяцев назад

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

EPSS

Процентиль: 37%
0.00158
Низкий

8.1 High

CVSS3

Дефекты

CWE-74