Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0318

Опубликовано: 15 янв. 2024
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
EPSS Низкий

Описание

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and 'Hostname/IP' parameters that will be triggered when items are loaded.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fireeye:hxtool:4.6:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00076
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 2 лет назад

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and 'Hostname/IP' parameters that will be triggered when items are loaded.

EPSS

Процентиль: 23%
0.00076
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79