Описание
Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
EPSS
5.4 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.
Уязвимость систем безопасности электронной почты FireEye EX 3500, 5500, 8500, позволяющая нарушителю выполнить межсайтовй скриптинг
EPSS
5.4 Medium
CVSS3
6.1 Medium
CVSS3