Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr7f-hm66-4cpv

Опубликовано: 02 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.

EPSS

Процентиль: 26%
0.00092
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.

EPSS

Процентиль: 26%
0.00092
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352