Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrx5-m699-v9jg

Опубликовано: 30 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

EPSS

Процентиль: 38%
0.00168
Низкий

7.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.6
nvd
почти 2 года назад

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

EPSS

Процентиль: 38%
0.00168
Низкий

7.6 High

CVSS3

Дефекты

CWE-79