Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh3w-9cjp-3cf8

Опубликовано: 13 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

EPSS

Процентиль: 13%
0.00042
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.4
nvd
9 месяцев назад

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

EPSS

Процентиль: 13%
0.00042
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79