CVE-2023-49119
Stored Cross-Site Scripting (XSS) via img Tags in GROWI
GROWI におけるimg タグによる格納型XSS (クロスサイトスクリプティング)
In GROWI v6.0.0 and earlier versions, it is possible to bypass security mechanisms and execute XSS when rendering Markdown as HTML.
Disclosure Date
2023/12/13
Credit
azara (@a_zara_n)