Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jvq4-qh39-564c

Опубликовано: 20 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates that chained built-in filter functions to generate XSS payloads. These payloads can be rendered by the Logpoint Report Template engine, making it vulnerable to cross-site scripting (XSS) attacks.

An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates that chained built-in filter functions to generate XSS payloads. These payloads can be rendered by the Logpoint Report Template engine, making it vulnerable to cross-site scripting (XSS) attacks.

EPSS

Процентиль: 6%
0.00024
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.9
nvd
7 месяцев назад

An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates that chained built-in filter functions to generate XSS payloads. These payloads can be rendered by the Logpoint Report Template engine, making it vulnerable to cross-site scripting (XSS) attacks.

EPSS

Процентиль: 6%
0.00024
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79