Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5pf-fxhf-9c22

Опубликовано: 22 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

EPSS

Процентиль: 50%
0.00271
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 4 лет назад

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

CVSS3: 5.4
nvd
около 4 лет назад

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

CVSS3: 5.4
debian
около 4 лет назад

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows auth ...

EPSS

Процентиль: 50%
0.00271
Низкий

Дефекты

CWE-79