We found results for “


Date: September 13, 2022

In Alerta, versions v7.0.0 through v8.7.0 are vulnerable to Stored Cross-Site Scripting (XSS), in the full name field. When an admin clicks on the groups page the XSS payload will trigger and send authorization token to the attacker’s server which leads to admin account takeover.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Scripting (XSS)


CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us