Описание
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.5 (включая)
cpe:2.3:a:select2:select2:*:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00906
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.3
redhat
почти 7 лет назад
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
CVSS3: 6.1
debian
почти 7 лет назад
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich ...
CVSS3: 6.1
github
больше 3 лет назад
Improper Neutralization of Input During Web Page Generation in Select2
EPSS
Процентиль: 75%
0.00906
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79