Description
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8605 | In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator. |
References
| Link | Providers |
|---|---|
| https://github.com/b3log/solo/issues/12501 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:32:54.018Z
Reserved: 2018-09-10T00:00:00.000Z
Link: CVE-2018-16805
No data.
Status : Modified
Published: 2018-09-10T23:29:00.253
Modified: 2024-11-21T03:53:23.030
Link: CVE-2018-16805
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD