Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45176

Опубликовано: 10 июн. 2024
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
EPSS Низкий

Описание

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*
Версия до 018 (включая)

EPSS

Процентиль: 56%
0.0034
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 1 года назад

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.

EPSS

Процентиль: 56%
0.0034
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79