Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-27083

Опубликовано: 29 фев. 2024
Источник: nvd
CVSS3: 4.3
CVSS3: 6.1
EPSS Низкий

Описание

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:*
Версия от 4.1.4 (включая) до 4.2.1 (исключая)

EPSS

Процентиль: 70%
0.00629
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

CVSS3: 4.3
debian
почти 2 года назад

Flask-AppBuilder is an application development framework, built on top ...

CVSS3: 4.3
github
почти 2 года назад

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

EPSS

Процентиль: 70%
0.00629
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79