Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.vulnerability-lab.com/get_content.php?id=1608 | third party advisory exploit |
https://vulners.com/securityvulns/SECURITYVULNS:DOC:32625 | third party advisory exploit |
https://github.com/NodeBB/NodeBB/pull/3371 | third party advisory patch |
https://github.com/NodeBB/NodeBB/compare/56b79a9...4de7529 | third party advisory release notes |