Логотип exploitDog
bind:CVE-2022-4068
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4068

Количество 2

Количество 2

nvd логотип

CVE-2022-4068

около 3 лет назад

A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-f3hw-3h74-wr98

около 3 лет назад

Cross-site Scripting in librenms/librenms

CVSS3: 7.6
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4068

A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.

CVSS3: 5.4
54%
Средний
около 3 лет назад
github логотип
GHSA-f3hw-3h74-wr98

Cross-site Scripting in librenms/librenms

CVSS3: 7.6
54%
Средний
около 3 лет назад

Уязвимостей на страницу