Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmvw-wjx4-2qxx

Опубликовано: 07 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.9
CVSS3: 7.9

Описание

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.

EPSS

Процентиль: 18%
0.00057
Низкий

5.9 Medium

CVSS4

7.9 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.9
nvd
4 месяца назад

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.

EPSS

Процентиль: 18%
0.00057
Низкий

5.9 Medium

CVSS4

7.9 High

CVSS3

Дефекты

CWE-22