CVE-2016-5061
MEDIUMAternity < 9.0 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3) getExternalURL, or (4) retrieveTrustedUrl page.
Scores
CVSS v3
6.1
EPSS
0.0029
EPSS Percentile
52.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
aternity/aternity
< 9.0
n/a/n/a
Timeline
Published
Sep 29, 2016
Tracked Since
Feb 18, 2026