Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22876

Опубликовано: 19 янв. 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicious HTML file with Javascript code that will be executed in the context of the The Hive application using a specific URL. The vulnerability can be used to coerce a victim account to perform specific actions on the application as helping an analyst becoming administrator.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:strangebee:thehive:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 5.1.9 (включая)
cpe:2.3:a:strangebee:thehive:*:*:*:*:*:*:*:*
Версия от 5.2.0 (включая) до 5.2.8 (включая)

EPSS

Процентиль: 47%
0.00241
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 2 лет назад

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicious HTML file with Javascript code that will be executed in the context of the The Hive application using a specific URL. The vulnerability can be used to coerce a victim account to perform specific actions on the application as helping an analyst becoming administrator.

EPSS

Процентиль: 47%
0.00241
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79