CVE-2023-4892

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/09/2023
Last modified:
26/09/2023

Description

Teedy v1.11 has a vulnerability in its text editor that allows events<br /> <br /> to be executed in HTML tags that an attacker could manipulate. Thanks<br /> <br /> to this, it is possible to execute malicious JavaScript in the webapp.<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sismics:teedy:1.11:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools