CVE-2017-1000442 Information
Feb 14, 2021
cve
Description
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://www.passbolt.com/incidents/20170914_xss_on_resource_urls https://www.passbolt.com/incidents/20170914_xss_on_resource_urls https://www.passbolt.com/release/notesSeptember Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: