Логотип exploitDog
bind:CVE-2022-42908
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42908

Количество 2

Количество 2

nvd логотип

CVE-2022-42908

около 3 лет назад

WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-fgm8-jrv2-6fww

около 3 лет назад

WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42908

WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-fgm8-jrv2-6fww

WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.

CVSS3: 5.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу