Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2018-11352] Wallabag 2.2.3 to 2.3.2 - Stored Cross-Site Scripting

Summary

A stored XSS in Wallabag 2.2.3 through 2.3.2 (CVE-2018-11352) hides in the settings page and fires when an administrator visits it, enabling session theft.
Published
Collected

original ↗

Related coverage

back