Описание
LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser role) can inject a cross-site scripting payload into the rule id parameter. Then, after any user with access to this service (e.g. admin) tries make any modifications with the rule (update, run, stop, delete), a payload acts in the victim's browser. Version 2.0.8 fixes the issue.
Ссылки
EPSS
Процентиль: 51%
0.00282
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
11 месяцев назад
LF Edge eKuiper allows Stored XSS in Rules Functionality
EPSS
Процентиль: 51%
0.00282
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79