Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21584

Опубликовано: 12 мар. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a specific operation, an arbitrary script may be executed on the web browser of the user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pleasanter:pleasanter:*:*:*:*:*:*:*:*
Версия до 1.3.49.0 (включая)

EPSS

Процентиль: 72%
0.00725
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
почти 2 года назад

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a specific operation, an arbitrary script may be executed on the web browser of the user.

EPSS

Процентиль: 72%
0.00725
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79