Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9wm-cxxw-876h

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.

EPSS

Процентиль: 5%
0.00021
Низкий

8.5 High

CVSS4

Дефекты

CWE-352

Связанные уязвимости

nvd
11 дней назад

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.

EPSS

Процентиль: 5%
0.00021
Низкий

8.5 High

CVSS4

Дефекты

CWE-352