Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46181

Опубликовано: 29 дек. 2022
Источник: nvd
CVSS3: 6.1
CVSS3: 5.4
EPSS Низкий

Описание

Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts if another user opened a link. The attacker could potentially take over the account of the user that clicked the link. The Gotify UI won't natively expose such a malicious link, so an attacker has to get the user to open the malicious link in a context outside of Gotify. The vulnerability has been fixed in version 2.2.2. As a workaround, you can block access to non image files via a reverse proxy in the ./image directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gotify:server:*:*:*:*:*:*:*:*
Версия до 2.2.2 (исключая)

EPSS

Процентиль: 60%
0.00397
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
github
около 3 лет назад

gotify/server vulnerable to Cross-site Scripting in the application image file upload

EPSS

Процентиль: 60%
0.00397
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79