Описание
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jedox:jedox:2020.2.5:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01667
Низкий
5.4 Medium
CVSS3
9.6 Critical
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
почти 3 года назад
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.
EPSS
Процентиль: 82%
0.01667
Низкий
5.4 Medium
CVSS3
9.6 Critical
CVSS3
Дефекты
CWE-79
CWE-79