Описание
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-34618
- https://cwe.mitre.org/data/definitions/79.html
- https://docs.mealie.io/changelog/v0.5.6
- https://gainsec.com/2022/08/02/cve-2022-34613-cve-2022-34618-cve-2022-34619-xss-file-upload-and-more
- https://hub.docker.com/r/hkotel/mealie
- https://huntr.dev/bounties/aa610613-6ebb-4544-9aa6-046dc28fe4ff
Связанные уязвимости
CVSS3: 5.4
nvd
больше 3 лет назад
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.