Lucene search

K
osvGoogleOSV:GHSA-X7R7-WMJ8-VV5G
HistoryMay 19, 2022 - 12:00 a.m.

Cross-site Scripting in OctoPrint

2022-05-1900:00:31
Google
osv.dev
14
cross-site scripting
octoprint
dom
github
javascript injection
account takeover
phishing

EPSS

0.002

Percentile

56.5%

Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. The login endpoint allows for javascript injection which may lead to account takeover in a phishing scenario.

EPSS

0.002

Percentile

56.5%

Related for OSV:GHSA-X7R7-WMJ8-VV5G