Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q55c-hmpf-6h2g

Опубликовано: 20 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

AzuraCast/AzuraCast vulnerable to cross-site scripting

AzuraCast/AzuraCast prior to version 0.18.0 is vulnerable to stored cross-site scripting. An issue was identified where a user who already had an AzuraCast account could update their display name to inject malicious JavaScript into the header menu of the site. In a majority of cases, this menu is only visible to the current logged-in user (pages like the Administer Users page are unaffected by this vulnerability), but if a higher-privileged administrator uses the Log In As feature to masquerade as a user, then the JavaScript injection could exfiltrate certain data. Anonymous members of the public cannot exploit this vulnerability in an AzuraCast installation, so it is primarily of concern for multi-tenant installations (i.e. resellers).

Пакеты

Наименование

azuracast/azuracast

composer
Затронутые версииВерсия исправления

< 0.18.0

0.18.0

EPSS

Процентиль: 26%
0.0009
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
почти 3 года назад

Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.

EPSS

Процентиль: 26%
0.0009
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79