Описание
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
Ссылки
- PatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.6 (исключая)
cpe:2.3:a:kiwitcms:kiwi_tcms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00327
Низкий
7.1 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
EPSS
Процентиль: 55%
0.00327
Низкий
7.1 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79