6.1

CVE-2018-1000642

FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Flightairmap ≫ Flightairmap Version 0.1 Update beta1
Flightairmap ≫ Flightairmap Version 0.2 Update beta1
Flightairmap ≫ Flightairmap Version 0.5 Update beta1
Flightairmap ≫ Flightairmap Version 0.6 Update beta1
Flightairmap ≫ Flightairmap Version 1.0 Update beta1
Flightairmap ≫ Flightairmap Version 1.0 Update beta10
Flightairmap ≫ Flightairmap Version 1.0 Update beta11
Flightairmap ≫ Flightairmap Version 1.0 Update beta12
Flightairmap ≫ Flightairmap Version 1.0 Update beta13
Flightairmap ≫ Flightairmap Version 1.0 Update beta14
Flightairmap ≫ Flightairmap Version 1.0 Update beta15
Flightairmap ≫ Flightairmap Version 1.0 Update beta16
Flightairmap ≫ Flightairmap Version 1.0 Update beta17
Flightairmap ≫ Flightairmap Version 1.0 Update beta18
Flightairmap ≫ Flightairmap Version 1.0 Update beta19
Flightairmap ≫ Flightairmap Version 1.0 Update beta2
Flightairmap ≫ Flightairmap Version 1.0 Update beta20
Flightairmap ≫ Flightairmap Version 1.0 Update beta21
Flightairmap ≫ Flightairmap Version 1.0 Update beta3
Flightairmap ≫ Flightairmap Version 1.0 Update beta4
Flightairmap ≫ Flightairmap Version 1.0 Update beta5
Flightairmap ≫ Flightairmap Version 1.0 Update beta6
Flightairmap ≫ Flightairmap Version 1.0 Update beta7
Flightairmap ≫ Flightairmap Version 1.0 Update beta8
Flightairmap ≫ Flightairmap Version 1.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.538
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://0dd.zone/2018/08/05/FlightAirMap-Reflected-XSS/
Third Party Advisory
https://github.com/Ysurac/FlightAirMap/issues/410
Third Party Advisory