templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8010 templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:47:13.983Z

Reserved: 2019-10-19T00:00:00

Link: CVE-2019-18209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-19T01:15:10.590

Modified: 2024-11-21T04:32:50.133

Link: CVE-2019-18209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.