Количество 2
Количество 2
CVE-2019-17557
почти 6 лет назад
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
CVSS3: 5.4
EPSS: Низкий
GHSA-6qj8-c27w-rp33
около 4 лет назад
Cross-site scripting in Apache Syncome EndUser
CVSS3: 5.4
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-17557 It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string. | CVSS3: 5.4 | 1% Низкий | почти 6 лет назад | |
GHSA-6qj8-c27w-rp33 Cross-site scripting in Apache Syncome EndUser | CVSS3: 5.4 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу
20