Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-02-22T09:48:20.873Z
Updated: 2024-08-01T22:59:32.284Z
Reserved: 2024-01-16T02:49:36.161Z
Link: CVE-2024-23349
Vulnrichment
Updated: 2024-08-01T22:59:32.284Z
NVD
Status : Awaiting Analysis
Published: 2024-02-22T10:15:08.427
Modified: 2024-02-22T19:07:27.197
Link: CVE-2024-23349
Redhat
No data.