Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-43796

Опубликовано: 15 окт. 2024
Источник: msrc
CVSS3: 4.7
EPSS Низкий

Описание

Описание отсутствует

Возможность эксплуатации

DOS

N/A

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
11 месяцев назад

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

CVSS3: 5
redhat
11 месяцев назад

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

CVSS3: 5
nvd
11 месяцев назад

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

CVSS3: 5
debian
11 месяцев назад

Express.js minimalist web framework for node. In express < 4.20.0, pas ...

CVSS3: 5
github
11 месяцев назад

express vulnerable to XSS via response.redirect()

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3