Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfhr-9grr-mhwq

Опубликовано: 14 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.  

If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.  

If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

EPSS

Процентиль: 8%
0.00028
Низкий

7.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.6
nvd
около 2 лет назад

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.   If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

EPSS

Процентиль: 8%
0.00028
Низкий

7.6 High

CVSS3

Дефекты

CWE-79