4.3

CVE-2013-5118

Exploit
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoodGood For Enterprise Version <= 2.2.3
GoodGood For Enterprise Version1.9.8
GoodGood For Enterprise Version1.9.9
GoodGood For Enterprise Version1.9.10
GoodGood For Enterprise Version2.0.0
GoodGood For Enterprise Version2.0.1
GoodGood For Enterprise Version2.0.2
GoodGood For Enterprise Version2.0.3.1464
GoodGood For Enterprise Version2.1.2.1510
GoodGood For Enterprise Version2.1.3.1513
GoodGood For Enterprise Version2.1.4.1518
GoodGood For Enterprise Version2.1.5.1551
GoodGood For Enterprise Version2.2.0.1575
GoodGood For Enterprise Version2.2.1.1591
GoodGood For Enterprise Version2.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.602
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.