Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x58f-rjp3-rh75

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.

EPSS

Процентиль: 35%
0.00145
Низкий

8.3 High

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 4.7
nvd
больше 2 лет назад

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.

EPSS

Процентиль: 35%
0.00145
Низкий

8.3 High

CVSS3

Дефекты

CWE-80