Описание
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.
Уязвимые конфигурации
Конфигурация 1Версия до 11.3.6 (исключая)Версия от 12.0.0 (включая) до 12.0.3 (исключая)
Одно из
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00443
Низкий
9.3 Critical
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.3
github
около 1 месяца назад
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.
EPSS
Процентиль: 38%
0.00443
Низкий
9.3 Critical
CVSS3
Дефекты
CWE-22