Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq7g-984r-4j7x

Опубликовано: 01 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

EPSS

Процентиль: 34%
0.0014
Низкий

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

EPSS

Процентиль: 34%
0.0014
Низкий

Дефекты

CWE-601