Логотип exploitDog
bind:CVE-2018-6824
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-6824

Количество 2

Количество 2

nvd логотип

CVE-2018-6824

около 8 лет назад

Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p8q6-h3fm-7g2m

больше 3 лет назад

Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6824

Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.

CVSS3: 6.1
0%
Низкий
около 8 лет назад
github логотип
GHSA-p8q6-h3fm-7g2m

Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу