Описание
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 18.0.0 (исключая)
cpe:2.3:a:diagrams:drawio:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.0183
Низкий
9.6 Critical
CVSS3
9.6 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-94
CWE-79
Связанные уязвимости
CVSS3: 9.6
github
почти 4 года назад
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
EPSS
Процентиль: 82%
0.0183
Низкий
9.6 Critical
CVSS3
9.6 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-94
CWE-79