Описание
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.
Ссылки
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.7.1 (исключая)Версия до 5.7.1 (исключая)Версия до 5.7.1 (исключая)
Одно из
cpe:2.3:a:groupsession:groupsession:*:*:*:*:bycloud:*:*:*
cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:*
cpe:2.3:a:groupsession:groupsession:*:*:*:*:zion:*:*:*
EPSS
Процентиль: 9%
0.00188
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
10 месяцев назад
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.
EPSS
Процентиль: 9%
0.00188
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79