Vulnerability CVE-2024-2692


Published: 2024-04-04

Description:
SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://fluidattacks.com/advisories/dezco/
https://github.com/siyuan-note/siyuan/

Copyright 2026, cxsecurity.com

 

Back to Top