8.4
CVE-2022-1803
- EPSS 1.61%
- Veröffentlicht 20.05.2022 22:16:40
- Zuletzt bearbeitet 21.11.2024 06:41:30
- CVE-Watchlists
- Unerledigt
Improper Restriction of Rendered UI Layers or Frames in polonel/trudesk
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trudesk Project ≫ Trudesk Version < 1.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.61% | 0.735 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.9 | 1.7 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:H
|
| NIST | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:P
|
| security@huntr.dev | 8.4 | 1.7 | 6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://github.com/polonel/trudesk/commit/6ea9db7a5cf300e3cbf0eab7e1d6da1155a2f7f8
https://huntr.dev/bounties/47cc6621-2474-40f9-ab68-3cf62389a124