Логотип exploitDog
bind:CVE-2022-38845
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-38845

Количество 2

Количество 2

nvd логотип

CVE-2022-38845

больше 3 лет назад

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p6h4-8jrv-52x7

больше 3 лет назад

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-38845

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p6h4-8jrv-52x7

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу