Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code via search tag function.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/shaarli/Shaarli/issues/2038 | issue tracking exploit |
https://github.com/shaarli/Shaarli/releases/tag/v0.13.0 | release notes |