A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/datenstrom/yellow/issues/321 |
|
History
Fri, 20 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:01:32.831Z
Reserved: 2018-05-04T00:00:00.000Z
Link: CVE-2018-10726
Updated: 2024-08-05T07:46:46.446Z
Status : Modified
Published: 2018-05-04T15:29:00.483
Modified: 2024-11-21T03:41:55.737
Link: CVE-2018-10726
No data.
OpenCVE Enrichment
No data.
Weaknesses