Lucene search

K
cveMitreCVE-2023-26912
HistoryMar 15, 2023 - 8:15 p.m.

CVE-2023-26912

2023-03-1520:15:10
CWE-79
mitre
web.nvd.nist.gov
39
cve-2023-26912
xss
vulnerability
xenv s-mall-ssm
nvd
security
code execution

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

22.9%

Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb 17, 2020, allows local attackers to execute arbitrary code via the evaluate button.

Affected configurations

Nvd
Node
s-mall-ssm_projects-mall-ssmRange<2020-02-17
VendorProductVersionCPE
s-mall-ssm_projects-mall-ssm*cpe:2.3:a:s-mall-ssm_project:s-mall-ssm:*:*:*:*:*:*:*:*

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

22.9%

Related for CVE-2023-26912