6.1

CVE-2019-1020010

Exploit
Misskey before 10.102.4 allows hijacking a user's token.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MisskeyMisskey Version >= 10.46.0 < 10.102.4
MisskeyMisskey Version >= 11.0.0 < 11.20.2
MisskeyMisskey Version11.0.0 Updatealpha1
MisskeyMisskey Version11.0.0 Updatealpha10
MisskeyMisskey Version11.0.0 Updatealpha2
MisskeyMisskey Version11.0.0 Updatealpha3
MisskeyMisskey Version11.0.0 Updatealpha4
MisskeyMisskey Version11.0.0 Updatealpha5
MisskeyMisskey Version11.0.0 Updatealpha6
MisskeyMisskey Version11.0.0 Updatealpha7
MisskeyMisskey Version11.0.0 Updatealpha8
MisskeyMisskey Version11.0.0 Updatebeta1
MisskeyMisskey Version11.0.0 Updatebeta10
MisskeyMisskey Version11.0.0 Updatebeta11
MisskeyMisskey Version11.0.0 Updatebeta12
MisskeyMisskey Version11.0.0 Updatebeta13
MisskeyMisskey Version11.0.0 Updatebeta14
MisskeyMisskey Version11.0.0 Updatebeta15
MisskeyMisskey Version11.0.0 Updatebeta16
MisskeyMisskey Version11.0.0 Updatebeta2
MisskeyMisskey Version11.0.0 Updatebeta3
MisskeyMisskey Version11.0.0 Updatebeta4
MisskeyMisskey Version11.0.0 Updatebeta5
MisskeyMisskey Version11.0.0 Updatebeta6
MisskeyMisskey Version11.0.0 Updatebeta7
MisskeyMisskey Version11.0.0 Updatebeta8
MisskeyMisskey Version11.0.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.593
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.