VulnerabilityModified
CVE-2008-3596
Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.
MEDIUM 4.3EPSS 1.07%
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- harmoni/harmoni
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31406Vendor Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=2040255&group_id=82171&atid=1098812Exploit
- http://www.securityfocus.com/bid/30637
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44394
- http://secunia.com/advisories/31406Vendor Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=2040255&group_id=82171&atid=1098812Exploit
- http://www.securityfocus.com/bid/30637
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44394
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.