Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwmj-q2x7-r6p4

Опубликовано: 11 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.

Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.

EPSS

Процентиль: 67%
0.00527
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
больше 1 года назад

Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.

EPSS

Процентиль: 67%
0.00527
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79