Описание
RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2021.2a (исключая)
cpe:2.3:a:ruiyanai:cloudiso:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks.
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79