Логотип exploitDog
bind:CVE-2020-15951
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15951

Количество 2

Количество 2

nvd логотип

CVE-2020-15951

больше 5 лет назад

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qwjj-3fhx-p5hh

больше 3 лет назад

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15951

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
github логотип
GHSA-qwjj-3fhx-p5hh

Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу