Score Risk Without Inflating the CVSS
Use CVSS-style reasoning to separate base technical severity from environmental risk context.
A reflected XSS is confirmed in an internal admin search page protected by SSO and used by privileged support staff. Separate exploitability facts from environmental context before choosing severity. The common shortcut is to mark any confirmed XSS as high or critical. That ignores access requirements, user interaction, cookie protections, and actual reachable impact. State access conditions The page requires SSO and an admin-support role. Access requirements affect exploitability. They do not erase risk, but they change who can reach the vulnerable path. State interaction needs A privileged user must click or load a crafted URL. User interaction changes likelihood…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in