Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1536

Опубликовано: 29 апр. 2022
Источник: nvd
CVSS3: 3.5
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:*
Версия до 1.10.9 (включая)

EPSS

Процентиль: 49%
0.00257
Низкий

3.5 Low

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
почти 4 года назад

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

EPSS

Процентиль: 49%
0.00257
Низкий

3.5 Low

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79