
We found results for “”
WS-2022-0299
Date: September 13, 2022
In Alerta, versions v7.0.0 through v8.7.0 are vulnerable to Stored Cross-Site Scripting (XSS), in the full name field. When an admin clicks on the groups page the XSS payload will trigger and send authorization token to the attacker’s server which leads to admin account takeover.
Language: Python
Severity Score
Severity Score
Weakness Type (CWE)
Cross-Site Scripting (XSS)
CWE-79CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |