ZeroHour

CVE-2022-41139

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.

Vendors
mitre
Products
caldera
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.