1.
bishopfox.com | blog | | original ↗ | #open-source | #vulnerability | #session-hijacking | #stored-xss
A stored XSS in Wallabag 2.2.3 through 2.3.2 (CVE-2018-11352) hides in the settings page and fires when an administrator visits it, enabling session theft.
Skip to content