Описание
MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.4 (исключая)
cpe:2.3:a:mygraph_project:mygraph:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00337
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
EPSS
Процентиль: 56%
0.00337
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79