Описание
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:getflightpath:flightpath:7.5:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00157
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
около 1 года назад
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.
EPSS
Процентиль: 37%
0.00157
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79