Логотип exploitDog
bind:CVE-2023-40024
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-40024

Количество 3

Количество 3

nvd логотип

CVE-2023-40024

больше 2 лет назад

ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a detailed license view that does not exist. Attackers can exploit this vulnerability to inject malicious scripts into the response generated by the `license_details_view` function. When unsuspecting users visit the page, their browsers will execute the injected scripts, leading to unauthorized actions, session hijacking, or stealing sensitive information. This issue has been addressed in release `32.5.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6xcx-gx7r-rccj

больше 2 лет назад

Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2023-06646

больше 2 лет назад

Уязвимость функции license_details_view инструмента сканирования и анализа открытого исходного кода программного обеспечения ScanCode.io, позволяющая нарушителю выполнить атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-40024

ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a detailed license view that does not exist. Attackers can exploit this vulnerability to inject malicious scripts into the response generated by the `license_details_view` function. When unsuspecting users visit the page, their browsers will execute the injected scripts, leading to unauthorized actions, session hijacking, or stealing sensitive information. This issue has been addressed in release `32.5.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6xcx-gx7r-rccj

Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-06646

Уязвимость функции license_details_view инструмента сканирования и анализа открытого исходного кода программного обеспечения ScanCode.io, позволяющая нарушителю выполнить атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу