Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ociredefzo

#51109de 53,635
4.3CVSS total
Vulnerabilidades · 1
PT-2015-6927
4.3
2015-07-08
Snorby · Snorby · CVE-2015-5460
**Name of the Vulnerable Software and Affected Versions** Snorby version 2.6.2 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `title` (cls.name variable) when creating a classification. **Recommendations** For Snorby version 2.6.2, as a temporary workaround, consider validating and sanitizing the `cls.name` variable to prevent injection of malicious scripts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.