Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q84v-pwf5-wm4x

Опубликовано: 20 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.

EPSS

Процентиль: 34%
0.00135
Низкий

3.5 Low

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 3.5
nvd
больше 2 лет назад

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.

EPSS

Процентиль: 34%
0.00135
Низкий

3.5 Low

CVSS3

Дефекты

CWE-77