Описание
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported).
Ссылки
- Release NotesThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- https://github.com/munkireport/munkireport-php/wiki/20200722-Reflected-XSS-In-Managedinstalls-ModuleThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- https://github.com/munkireport/munkireport-php/wiki/20200722-Reflected-XSS-In-Managedinstalls-ModuleThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6 (исключая)
cpe:2.3:a:managedinstalls_project:managedinstalls:*:*:*:*:*:munkireport:*:*
EPSS
Процентиль: 67%
0.00528
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
MunkiReport Managed Installs module Reflected Cross-Site Scripting (XSS) vulnerability
EPSS
Процентиль: 67%
0.00528
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79