Описание
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json input. Releases before version 21.12.22.1 are affected. A workaround exists that replaces one of the core JavaScript files embedded in the library. See the GHSA-5q7q-qqw2-hjq7 for workaround details.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- MitigationThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- MitigationThird Party Advisory
Уязвимые конфигурации
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
Связанные уязвимости
AjaxNetProfessional deserializes arbitrary JavaScript objects
Уязвимость фреймворка Ajax.NET Professional (AjaxPro), существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3
3.5 Low
CVSS2