NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-42515
Summary

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

Publication Date Nov. 1, 2024, 4:15 a.m.
Registration Date Nov. 1, 2024, noon
Last Update Nov. 2, 2024, 1:35 a.m.
Related information, measures and tools
Common Vulnerabilities List