Логотип exploitDog
bind:CVE-2019-10049
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-10049

Количество 3

Количество 3

nvd логотип

CVE-2019-10049

больше 6 лет назад

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2019-10049

больше 6 лет назад

It is possible for an attacker with regular user access to the web app ...

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-h7cq-wjp9-9pr6

больше 3 лет назад

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10049

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

CVSS3: 7.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10049

It is possible for an attacker with regular user access to the web app ...

CVSS3: 7.3
0%
Низкий
больше 6 лет назад
github логотип
GHSA-h7cq-wjp9-9pr6

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

CVSS3: 7.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу