漏洞标题
XSS漏洞在Metabase中
漏洞描述信息
Metabase中的XSS漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
XSS vulnerability in Metabase
漏洞描述信息
Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to `/_internal` endpoints for Metabase. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Metabase 跨站脚本漏洞
漏洞描述信息
Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase 存在跨站脚本漏洞,该漏洞源于内部开发端点可能允许跨站点脚本 (XSS) 攻击。以下产品和版本受到影响:x.42 - x.42.3、x.41 - x.41.6、x.40 - x.40.7。
CVSS信息
N/A
漏洞类别
跨站脚本