Lucene search

K
vulnrichmentSNPSVULNRICHMENT:CVE-2024-0226
HistoryJan 09, 2024 - 5:41 p.m.

CVE-2024-0226 Stored Cross-Site Scripting in Synopsys Seeker

2024-01-0917:41:31
CWE-79
SNPS
github.com
synopsys seeker
stored cross-site scripting
vulnerability
2023.12.0
payload crafted

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-0226