Vulnerabilities
Vulnerable Software
Mitre:  >> Caldera  >> 2.9.0  Security Vulnerabilities
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-10-17
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-10-17
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-10-17
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).
CVSS Score
8.8
EPSS Score
0.093
Published
2022-01-12


Contact Us

Shodan ® - All rights reserved