Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8276

Опубликовано: 16 сент. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 9.8
EPSS Низкий

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Patika Global Technologies HumanSuite allows Cross-Site Scripting (XSS), Phishing.This issue affects HumanSuite: before 53.21.0.

EPSS

Процентиль: 19%
0.0006
Низкий

4.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 10
github
5 месяцев назад

Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Improper Control of Generation of Code ('Code Injection') vulnerability in Patika Global Technologies HumanSuite allows Input Data Manipulation, Format String Injection, Reflection Injection, Code Injection.This issue affects HumanSuite: before 53.21.0.

EPSS

Процентиль: 19%
0.0006
Низкий

4.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74