Disclosure Date 2023/06/29

CVE-2023-37298

Cross-site Scripting in Joplin

JoplinにおけるXSS (クロスサイトスクリプティング)

Credit

RyotaK

Description

Joplin before 2.11.5 allows XSS via a USE element in an SVG document.

Back