[CVE-2018-11352] Wallabag 2.2.3 to 2.3.2 - Stored Cross-Site Scripting
bishopfox.com | blog | CVE-2018-11352 | #open-source | #vulnerability | #session-hijacking | #stored-xss | #wallabag | #cve-2018-11352
Summary
A stored XSS in Wallabag 2.2.3 through 2.3.2 (CVE-2018-11352) hides in the settings page and fires when an administrator visits it, enabling session theft.
- Published
- Collected
Skip to content