Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39301

Опубликовано: 19 окт. 2022
Источник: nvd
CVSS3: 8.2
CVSS3: 5.4
EPSS Низкий

Описание

sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code in "Personal Center" - "Profile Picture Upload" allowing theft of the user's personal information. This issue has been patched in 1.1.2. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sra-admin_project:sra-admin:*:*:*:*:*:*:*:*
Версия до 1.1.1 (включая)

EPSS

Процентиль: 51%
0.00276
Низкий

8.2 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-80
CWE-434

EPSS

Процентиль: 51%
0.00276
Низкий

8.2 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-80
CWE-434