Логотип exploitDog
bind:CVE-2024-27083
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27083

Количество 4

Количество 4

ubuntu логотип

CVE-2024-27083

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-27083

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-27083

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fqxj-46wg-9v84

почти 2 года назад

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27083

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-27083

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-27083

Flask-AppBuilder is an application development framework, built on top ...

CVSS3: 4.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-fqxj-46wg-9v84

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

CVSS3: 4.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу