Описание
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
EPSS
Процентиль: 33%
0.00393
Низкий
7.3 High
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 7.3
github
2 дня назад
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
EPSS
Процентиль: 33%
0.00393
Низкий
7.3 High
CVSS3
Дефекты
CWE-79