CVE-2023-49119

Stored Cross-Site Scripting (XSS) via img Tags in GROWI

GROWI におけるimg タグによる格納型XSS (クロスサイトスクリプティング)

In GROWI v6.0.0 and earlier versions, it is possible to bypass security mechanisms and execute XSS when rendering Markdown as HTML.

Disclosure Date

2023/12/13

Credit

azara (@a_zara_n)

Reference