OneNav beta 0.9.12 allows XSS via... CVE-2021-38138

3.5 AV AC AU C I A
发布: 2021-08-05
修订: 2024-11-21

OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息