Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5x4-jpcc-h4rv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.

touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.

EPSS

Процентиль: 54%
0.00311
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
nvd
около 5 лет назад

touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.

EPSS

Процентиль: 54%
0.00311
Низкий

Дефекты

CWE-79