Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w66w-cmgq-cc2j

Опубликовано: 20 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.

In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.

EPSS

Процентиль: 52%
0.00287
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.

EPSS

Процентиль: 52%
0.00287
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79