Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pj89-mr75-5fmf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.

A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.

EPSS

Процентиль: 34%
0.00135
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.9
nvd
около 4 лет назад

A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.

EPSS

Процентиль: 34%
0.00135
Низкий

Дефекты

CWE-79