Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-44272: webcit: sanitize instant messages against XSS type stuff (f0dac5ff) · Commits · citadel / Citadel · GitLab

A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.

CVE
#xss#vulnerability#web#git#java#auth

Commit f0dac5ff authored Sep 15, 2023 by Art Cancro

Browse files

webcit: sanitize instant messages against XSS type stuff

parent 08ba8022

  • Changes 2

Hide whitespace changes

Inline Side-by-side

Supports Markdown

0% or .

You are about to add 0 people to the discussion. Proceed with caution.

Finish editing this message first!

Please register or sign in to comment

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907