Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhx8-cppg-v89v

Опубликовано: 18 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

** UNSUPPPORTED WHEN ASSIGNED **

Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the field MAIL_RCV. When a legitimate user attempts to access to the vulnerable page of the web application, the XSS payload will be executed.

** UNSUPPPORTED WHEN ASSIGNED **

Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the field MAIL_RCV. When a legitimate user attempts to access to the vulnerable page of the web application, the XSS payload will be executed.

EPSS

Процентиль: 24%
0.0008
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
больше 2 лет назад

Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the field MAIL_RCV. When a legitimate user attempts to access to the vulnerable page of the web application, the XSS payload will be executed.

CVSS3: 6.3
fstec
больше 2 лет назад

Уязвимость веб-приложения управления модульного источника бесперебойного питания MODULYS GP (MOD3GP-SY-120K), позволяющая нарушителю выполнять атаки с использованием межсайтовых сценариев (XSS)

EPSS

Процентиль: 24%
0.0008
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79