Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcgh-c3ww-gxh7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST parameter. The web application does not neutralize user-controllable input before displaying to users in a web page, which could allow a remote attacker authenticated with a user account to execute arbitrary code.

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST parameter. The web application does not neutralize user-controllable input before displaying to users in a web page, which could allow a remote attacker authenticated with a user account to execute arbitrary code.

EPSS

Процентиль: 57%
0.0035
Низкий

Связанные уязвимости

CVSS3: 6.3
nvd
почти 6 лет назад

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST parameter. The web application does not neutralize user-controllable input before displaying to users in a web page, which could allow a remote attacker authenticated with a user account to execute arbitrary code.

EPSS

Процентиль: 57%
0.0035
Низкий