VDB
CVE-2024-53257
CVE-2024-53257
PUBLISHED
CVSS 4.900000095367432 MEDIUM
Vitess allows HTML injection in /debug/querylogz & /debug/env
EPSS 0.06% · 18.3th percentile
Risk Scores
CVSS 3.1
4.900000095367432
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.06%
18.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| vitessio | vitess | 0, 19.0.9, 20.0.5 |
| vitessio | vitess | >= 0.21.0-rc1, < 21.0.1, >= 0.20.0-rc1, < 20.0.4, < 19.0.8 |
| vitess.io | vitess | 0.21.0-rc1, 0.20.0-rc1, 0 |
Exploit Intelligence
Timeline
- Jan 21, 1970 Security Advisory
- Dec 3, 2024 CVE Published
- Dec 3, 2024 PoC Published
- Dec 3, 2024 PoC Published
- Dec 4, 2024 EPSS Score
- Dec 16, 2024 CVE Updated
- Dec 21, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 24, 2025 EPSS Score
- Feb 10, 2025 EPSS Score
- Feb 27, 2025 EPSS Score
- Mar 3, 2025 Coalition ESS Score