Логотип exploitDog
bind:CVE-2021-35488
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-35488

Количество 2

Количество 2

nvd логотип

CVE-2021-35488

около 4 лет назад

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-x3c7-xr54-mc7w

больше 3 лет назад

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-35488

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVSS3: 6.1
13%
Средний
около 4 лет назад
github логотип
GHSA-x3c7-xr54-mc7w

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

13%
Средний
больше 3 лет назад

Уязвимостей на страницу