YunoHost 2.7.2 to 2.7.14 - Multiple Vulnerabilities
bishopfox.com | blog | #vulnerability | #session-hijacking | #stored-xss | #yunohost | #http-header-injection | #cve-2018-11348
Summary
YunoHost 2.7.2 to 2.7.14 vulnerabilities: stored XSS in profile fields (CVE-2018-11348) and an HTTP header injection (CVE-2018-11347) that together can hijack user sessions.
- Published
- Collected
Skip to content