CVE-2018-6835
08.02.2018, 07:29
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.Enginsight
Vendor | Product | Version |
---|---|---|
etherpad | etherpad | 𝑥 < 1.6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration