Описание
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 2.13 (включая)
cpe:2.3:a:nchsoftware:webdictate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00278
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
EPSS
Процентиль: 51%
0.00278
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79