CVE-2017-1000239: XSS
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000239?
CVE-2017-1000239 is considered a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2017-1000239?
To fix CVE-2017-1000239, upgrade InvoicePlane to the latest version that addresses this vulnerability.
Who is affected by CVE-2017-1000239?
Authenticated users of InvoicePlane version 1.4.10 are affected by CVE-2017-1000239.
What type of vulnerability is CVE-2017-1000239?
CVE-2017-1000239 is a stored cross-site scripting vulnerability that allows script injection.
What are the potential consequences of CVE-2017-1000239?
The potential consequences of CVE-2017-1000239 include malicious script execution in the browsers of users visiting the affected site.