CVE-2018-12255: XSS
Published Jul 3, 2018
·Updated
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
Affected Software
1 affected component
InvoicePlane InvoicePlane=1.5.10
Event History
Jul 3, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12255?
The severity of CVE-2018-12255 is considered to be moderate due to the presence of an XSS vulnerability.
2
How do I fix CVE-2018-12255?
To fix CVE-2018-12255, it is recommended to sanitize user inputs in the 'Quote PDF Password(Optional)' field.
3
What software is affected by CVE-2018-12255?
CVE-2018-12255 affects InvoicePlane version 1.5.10.
4
Can CVE-2018-12255 exploit user data?
Yes, CVE-2018-12255 can potentially exploit user data via XSS attacks.
5
Is there a patch available for CVE-2018-12255?
Yes, users should look for updates or patches from InvoicePlane to mitigate CVE-2018-12255.