H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.com/bounties/9881569f-dc2a-437e-86b0-20d4b70ae7af | third party advisory exploit |