Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m862-4wg2-7pg7

Опубликовано: 16 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Improper Control of Generation of Code ('Code Injection') vulnerability in Patika Global Technologies HumanSuite allows Input Data Manipulation, Format String Injection, Reflection Injection, Code Injection.This issue affects HumanSuite: before 53.21.0.

Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Improper Control of Generation of Code ('Code Injection') vulnerability in Patika Global Technologies HumanSuite allows Input Data Manipulation, Format String Injection, Reflection Injection, Code Injection.This issue affects HumanSuite: before 53.21.0.

EPSS

Процентиль: 19%
0.0006
Низкий

10 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Patika Global Technologies HumanSuite allows Cross-Site Scripting (XSS), Phishing.This issue affects HumanSuite: before 53.21.0.

EPSS

Процентиль: 19%
0.0006
Низкий

10 Critical

CVSS3

Дефекты

CWE-74