CVE-2024-25874

EPSS 0.08%

Enhavo Cross-site Scripting vulnerability

發布日:2024/2/22修改日:2024/11/29

描述

A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Create Tag text field.

受影響套件(1)

參考連結(4)