Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24301

Опубликовано: 08 авг. 2020
Источник: redhat
CVSS3: 7.3

Описание

Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7hapi-fhir-baseNot affected
Red Hat Fuse 7hapi-fhir-clientNot affected
Red Hat Fuse 7hapi-fhir-structures-dstu2Not affected
Red Hat Fuse 7hapi-fhir-structures-dstu3Not affected
Red Hat Fuse 7hapi-fhir-utilitiesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1888307hapi-fhir: XSS vulnerability in Testpage Overlay via specially crafted URL

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

github
больше 3 лет назад

Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

7.3 High

CVSS3