Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-62g7-fpv9-v95f: Inventree vulnerable to Stored Cross-site Scripting

Inventree prior to 0.8.3 is vulnerable to stored cross-site scripting by uploading SVG files. Version 0.8.3 contains a patch for this issue.

ghsa
#xss#git

Inventree vulnerable to Stored Cross-site Scripting

Moderate severity GitHub Reviewed Published Sep 30, 2022 • Updated Oct 3, 2022

Related news

CVE-2022-3355

Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.