Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r342-8mgp-q73j

Опубликовано: 12 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.

A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79