Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v87v-crjf-8qv4

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

EPSS

Процентиль: 48%
0.00251
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5
nvd
около 4 лет назад

An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

EPSS

Процентиль: 48%
0.00251
Низкий

Дефекты

CWE-79