Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r488-7mj5-p3cj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal and replay authentication credentials via an IMG tag in the desc parameter ("Ticket Description" field) that points to a URL that captures referer URLs, possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs.

new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal and replay authentication credentials via an IMG tag in the desc parameter ("Ticket Description" field) that points to a URL that captures referer URLs, possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs.

EPSS

Процентиль: 71%
0.00661
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal and replay authentication credentials via an IMG tag in the desc parameter ("Ticket Description" field) that points to a URL that captures referer URLs, possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs.

EPSS

Процентиль: 71%
0.00661
Низкий