Skip to main content
PENETRATION-TESTING5 MIN READ

Score Risk Without Inflating the CVSS

Use CVSS-style reasoning to separate base technical severity from environmental risk context.

A reflected XSS is confirmed in an internal admin search page protected by SSO and used by privileged support staff. Separate exploitability facts from environmental context before choosing severity. The common shortcut is to mark any confirmed XSS as high or critical. That ignores access requirements, user interaction, cookie protections, and actual reachable impact. State access conditions The page requires SSO and an admin-support role. Access requirements affect exploitability. They do not erase risk, but they change who can reach the vulnerable path. State interaction needs A privileged user must click or load a crafted URL. User interaction changes likelihood…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us