Описание
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6.
Ссылки
- Product
- Patch
- ExploitThird Party Advisory
- Product
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2023.12.6 (исключая)
cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00238
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-20
CWE-79
EPSS
Процентиль: 47%
0.00238
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-20
CWE-79