Логотип exploitDog
bind:CVE-2024-47590
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47590

Количество 3

Количество 3

nvd логотип

CVE-2024-47590

около 1 года назад

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-5pj7-9h42-mfx3

около 1 года назад

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2024-09703

около 1 года назад

Уязвимость веб-диспетчера SAP Web Dispatcher, связанная с неполной фильтрацией специальных элементов, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-47590

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-5pj7-9h42-mfx3

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

CVSS3: 8.8
1%
Низкий
около 1 года назад
fstec логотип
BDU:2024-09703

Уязвимость веб-диспетчера SAP Web Dispatcher, связанная с неполной фильтрацией специальных элементов, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 8.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу