Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5950

Опубликовано: 06 нояб. 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 6.1
EPSS Низкий

Описание

Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This vulnerability is fixed in version 0.7.0-04 and a patch is available to download. Patches are also available for version 0.6.9 (0.6.9-1).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*
Версия до 0.6.9-1 (исключая)
cpe:2.3:a:rapid7:velociraptor:0.7.0:-:*:*:*:*:*:*
cpe:2.3:a:rapid7:velociraptor:0.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:rapid7:velociraptor:0.7.0-3:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

8.6 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 8.6
github
больше 2 лет назад

Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This vulnerability is fixed in version 0.7.0-04 and a patch is available to download. Patches are also available for version 0.6.9 (0.6.9-1).

EPSS

Процентиль: 20%
0.00063
Низкий

8.6 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79