CVE-2023-5084: Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp

3.9 CVSS

Description

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.

Classification

CVE ID: CVE-2023-5084

CVSS Base Severity: LOW

CVSS Base Score: 3.9

Affected Products

Vendor: hestiacp

Product: hestiacp/hestiacp

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 27.82% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://huntr.dev/bounties/f3340570-6e59-4c72-a7d1-d4b829b4fb45
https://github.com/hestiacp/hestiacp/pull/4013/commits/5131f5a966759df77477fdf7f29daa2bda93b1ff

Timeline