-
When i click to note function and commend with payload `"2">"`
![download (2)](https://github.com/user-attachments/assets/94fdb475-c4fb-437b-875a-2d8102300d86)
After save note will pop up such a…
-
https://www.cve.org/CVERecord?id=CVE-2024-33916
-
XSS vulnerability at the "Lead" function. When i create a tag with payload `"2">"` example like image bellow:
![download](https://github.com/user-attachments/assets/36cd7d27-83e1-4eb7-8d71-6caebe82…
-
# Summary
A reflected Cross Site Scripting (XSS) vulnerability exists in idcCMS V1.60 due to improper sanitization of the $idName parameter in `/inc/classProvCity.php`.
# Details
idcCMS V1.60 suf…
-
Recently, our team discovered a security vulnerability due to incomplete XSS filtering.
**Loaction:**
https://github.com/phpipam/phpipam/blob/master/app/admin/instructions/preview.php#L22
![image](…
-
In ***AttributeSetFilter***, multiple parameters are not ***XSS*** filtered
*cn.keking.web.filter.AttributeSetFilter#setWatermarkAttribute*
![image](https://user-images.githubusercontent.com/5064738…
S2eTo updated
3 months ago
-
### Checklist
- [X] I've looked at the [documentation](https://summernote.org/deep-dive/) to make sure the behavior isn't documented and expected.
- [X] I'm sure this is an issue with Summernote, not…
-
Hello,
it seems no operation is done, on form submission or on access to quill.html, to ensure that the HTML tags of the quill field are secure and correspond to the allowed tags of the JS widget.
…
pakal updated
2 months ago
-
Package: jquery-ui@1.13.1 or above.
Vulnerability Title: [CVE-2024-30875] CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vulnerability Description:
A C…
-
**Description**
DedeCMS-V5.7.111 has Reflective XSS vulnerabilities in imgstick and v parameters of selectimages.php
**Proof of Concept**
http://target-ip/uploads/include/dialog/select_images.php…