Количество 3
Количество 3
CVE-2021-25938
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.
CVE-2021-25938
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross ...
GHSA-fm33-4p7j-3jhr
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-25938 In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers. | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-25938 In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross ... | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
GHSA-fm33-4p7j-3jhr In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу