You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
wrongecho
published
GHSA-hw47-q7r3-m8pjMar 5, 2023
Package
No package listed
Affected versions
Commits prior to 75da31d9915a947339a0de95281db18c17aa933a
Patched versions
75da31d9915a947339a0de95281db18c17aa933a
Description
Impact
ITFlow (Beta commits prior to 75da31d) is affected by persistent XSS vulnerabilities.
An authenticated application user could execute arbitrary web scripts or HTML in the browser context of other application users by injecting a crafted payload.
Patches
This issues have been patched in commit 75da31d, available via the normal update process.
Acknowledgements
We would like to thank @10splayaSec & @bauluk for their responsible disclosure of these issues.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as <, >, and & that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
Learn more on MITRE.
Impact
Patches
Acknowledgements