Логотип exploitDog
bind:CVE-2019-17127
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-17127

Количество 2

Количество 2

nvd логотип

CVE-2019-17127

около 6 лет назад

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4wv5-g426-4246

больше 3 лет назад

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-17127

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

CVSS3: 6.1
2%
Низкий
около 6 лет назад
github логотип
GHSA-4wv5-g426-4246

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу