Описание
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:adive:framework:2.0.8:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00168
Низкий
7.6 High
CVSS3
7.4 High
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 7.6
github
почти 2 года назад
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.
EPSS
Процентиль: 38%
0.00168
Низкий
7.6 High
CVSS3
7.4 High
CVSS3
Дефекты
CWE-79