CVE-2018-18553

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT

Description

Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.

Not Just A Notepad! (golang + mongodb) http://leanote.org
GitHubGitHub
11.7K