CVE-2017-11594
24.07.2017, 01:29
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.
Vendor | Product | Version |
---|---|---|
loomio | loomio | 1.0.0 |
loomio | loomio | 1.1.0 |
loomio | loomio | 1.2.0 |
loomio | loomio | 1.3.0 |
loomio | loomio | 1.4.0 |
loomio | loomio | 1.5.0 |
loomio | loomio | 1.6.0 |
loomio | loomio | 1.7.0 |
𝑥
= Vulnerable software versions
References