Disclosure Date 2023/06/29

CVE-2023-37299

Cross-site Scripting in Joplin

JoplinにおけるXSS (クロスサイトスクリプティング)

Credit

RyotaK

Description

Joplin before 2.11.5 allows XSS via an AREA element of an image map.

Back