Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmmq-6pp3-rf2g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)

EPSS

Процентиль: 63%
0.00441
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-74

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)

EPSS

Процентиль: 63%
0.00441
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-74