Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpxw-mhc6-mv6v

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

EPSS

Процентиль: 51%
0.00276
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 16 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

nvd
почти 16 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

debian
почти 16 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the chara ...

EPSS

Процентиль: 51%
0.00276
Низкий

Дефекты

CWE-79