Описание
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Product
- ExploitThird Party AdvisoryVDB Entry
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.7 (исключая)
cpe:2.3:a:wyomind:help_desk:*:*:*:*:*:magento_2:*:*
EPSS
Процентиль: 30%
0.00111
Низкий
9 Critical
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 9
github
почти 3 года назад
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
EPSS
Процентиль: 30%
0.00111
Низкий
9 Critical
CVSS3
Дефекты
CWE-79
CWE-79