Описание
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
Ссылки
- ExploitMailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Patch
- ExploitVendor Advisory
- ExploitMailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Patch
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:kallithea-scm:kallithea:0.1:*:*:*:*:*:*:*
cpe:2.3:a:kallithea-scm:kallithea:0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00372
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
больше 8 лет назад
Multiple cross-site scripting (XSS) vulnerabilities in the administrat ...
CVSS3: 5.4
github
больше 3 лет назад
Kallithea cross-site scripting (XSS) vulnerability
EPSS
Процентиль: 58%
0.00372
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79