Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27778

Опубликовано: 01 июн. 2022
Источник: nvd
CVSS3: 4.9
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hcltech:traveler:*:*:*:*:*:*:*:*
Версия до 12.0.1.0 (включая)

EPSS

Процентиль: 36%
0.00149
Низкий

4.9 Medium

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

EPSS

Процентиль: 36%
0.00149
Низкий

4.9 Medium

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79