Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w826-hvm4-82xh

Опубликовано: 01 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

EPSS

Процентиль: 49%
0.00255
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 8.2
nvd
больше 3 лет назад

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

EPSS

Процентиль: 49%
0.00255
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-79