Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrr8-9vrv-c2gc

Опубликовано: 18 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.

EPSS

Процентиль: 65%
0.00502
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
12 месяцев назад

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.

EPSS

Процентиль: 65%
0.00502
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-20