Описание
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
Ссылки
- Exploit
- Exploit
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:cerberus:cerberus_helpdesk:2.7:*:*:*:*:*:*:*
cpe:2.3:a:cerberus:cerberus_helpdesk:2.7.1_development_release:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06618
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
EPSS
Процентиль: 91%
0.06618
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other