Headline
GHSA-62g7-fpv9-v95f: Inventree vulnerable to Stored Cross-site Scripting
Inventree prior to 0.8.3 is vulnerable to stored cross-site scripting by uploading SVG files. Version 0.8.3 contains a patch for this issue.
Inventree vulnerable to Stored Cross-site Scripting
Moderate severity GitHub Reviewed Published Sep 30, 2022 • Updated Oct 3, 2022
Related news
CVE-2022-3355
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.