Логотип exploitDog
bind:CVE-2022-28820
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-28820

Количество 2

Количество 2

nvd логотип

CVE-2022-28820

почти 4 года назад

ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker must provide a link to someone with access to AEM Author, and could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. The exploitation of this issue requires user interaction in order to be successful.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w5m2-299g-rff5

почти 4 года назад

Page Compare Reflected Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-28820

ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker must provide a link to someone with access to AEM Author, and could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. The exploitation of this issue requires user interaction in order to be successful.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-w5m2-299g-rff5

Page Compare Reflected Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
почти 4 года назад

Уязвимостей на страницу