Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fmq-6mh8-47mj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An XSS vulnerability in the auto-complete function of the description field (for new or edited transactions) in Firefly III before 5.4.5 allows the user to execute JavaScript via suggested transaction titles. NOTE: this is exploitable only in a non-default configuration where Content Security Policy headers are disabled.

An XSS vulnerability in the auto-complete function of the description field (for new or edited transactions) in Firefly III before 5.4.5 allows the user to execute JavaScript via suggested transaction titles. NOTE: this is exploitable only in a non-default configuration where Content Security Policy headers are disabled.

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

Дефекты

CWE-79