Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvc3-xwr8-2mgj

Опубликовано: 24 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.

Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.

EPSS

Процентиль: 32%
0.00126
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.

EPSS

Процентиль: 32%
0.00126
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79