Описание
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:dataparksearch:dataparksearch:4.16:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.17:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.18:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.19:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.20:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.21:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.22:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.23:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.24:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.25:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.26:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.27:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.28:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.29:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.30:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.31:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.32:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.33:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.34:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.35:*:*:*:*:*:*:*
cpe:2.3:a:dataparksearch:dataparksearch:4.36:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00427
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
EPSS
Процентиль: 62%
0.00427
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other