Описание
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.
Уязвимые конфигурации
Одно из
EPSS
7.2 High
CVSS3
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
Improper neutralization of input during web page generation ('Cross-si ...
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.
EPSS
7.2 High
CVSS3
6.1 Medium
CVSS3