Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcwm-cq8f-8h8f

Опубликовано: 08 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.

EPSS

Процентиль: 71%
0.00664
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 1 года назад

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.

EPSS

Процентиль: 71%
0.00664
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79