RSS   Vulnerabilities for 'Akiee'   RSS

2018-06-26
 
CVE-2018-1000543

CWE-79
 

 
Akiee version 0.0.3 contains a XSS leading to code execution due to the use of node integration vulnerability in "Details" of a task is not validated that can result in XSS leading to abritrary code execution. This attack appear to be exploitable via The attacker tricks the victim into opening a crafted markdown.

 


Copyright 2018, cxsecurity.com

 

Back to Top