A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/monicahq/monica/releases | patch |
https://github.com/Crypt0Cr33py/monicahqvuln | exploit |
https://www.monicahq.com | product |