CVE-2017-1000239

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/11/2017
Last modified:
20/04/2025

Description

InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invoiceplane:invoiceplane:1.4.10:*:*:*:*:*:*:*