leanote vulnerable to cross-site scripting
Moderate severity
GitHub Reviewed
Published
Dec 21, 2022
to the GitHub Advisory Database
•
Updated Oct 20, 2023
Description
Published by the National Vulnerability Database
Dec 21, 2022
Published to the GitHub Advisory Database
Dec 21, 2022
Reviewed
Oct 20, 2023
Last updated
Oct 20, 2023
A vulnerability, which was classified as problematic, has been found in leanote. This issue affects the function define of the file
public/js/plugins/history.js
. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The name of the patch is https:/github.com/leanote/leanote/commit/0f9733c890077942150696dcc6d2b1482b7a0a19. It is recommended to apply a patch to fix this issue. The identifier VDB-216461 was assigned to this vulnerability.References