Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2021-47908
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    6 packages
    • nnd
    • nim1
    • nim2
    • nim-2_0
    • lixStatic
    • nixStatic
  • @jopejoe1 dismissed
Ultimate POS 4.4 Persistent Cross-Site Scripting via Product Name

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

Affected products

Unknown
  • ==4.4
Ignored packages (6)

pkgs.nim1

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

pkgs.nim2

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

pkgs.nim-2_0

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

Not present in nixpkgs