Описание
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2020 (исключая)
Одно из
cpe:2.3:a:subnet:powersystem_center:*:*:*:*:*:*:*:*
cpe:2.3:a:subnet:powersystem_center:2020:-:*:*:*:*:*:*
cpe:2.3:a:subnet:powersystem_center:2020:u10:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00042
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.5
github
больше 2 лет назад
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications.
EPSS
Процентиль: 13%
0.00042
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79