| 概要 | Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry. |
|---|---|
| 公表日 | 2024年11月1日4:15 |
| 登録日 | 2024年11月1日12:00 |
| 最終更新日 | 2024年11月2日1:35 |