Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gist.github.com/enferas/e4ab1aedd9727c3b09c7d0154a052199 | third party advisory exploit |
https://gist.github.com/enferas/e8fff9261526fdf51808c39b3004e1b5 | third party advisory exploit |