CVE-2021-46888
21.05.2023, 20:15
An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.
Vendor | Product | Version |
---|---|---|
hledger | hledger | 𝑥 < 1.23 |
𝑥
= Vulnerable software versions
References