Описание
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known
EPSS
Процентиль: 11%
0.00036
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1021
Связанные уязвимости
CVSS3: 5.4
github
3 месяца назад
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known
EPSS
Процентиль: 11%
0.00036
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1021