Teedy v1.11 has a vulnerability in its text editor that allows events
to be executed in HTML tags that an attacker could manipulate. Thanks
to this, it is possible to execute malicious JavaScript in the webapp.
References
Link | Resource |
---|---|
https://fluidattacks.com/advisories/freebird | Exploit Third Party Advisory |
https://teedy.io | Product |
https://fluidattacks.com/advisories/freebird | Exploit Third Party Advisory |
https://teedy.io | Product |
Configurations
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-25 16:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4892
Mitre link : CVE-2023-4892
CVE.ORG link : CVE-2023-4892
JSON object : View
Products Affected
sismics
- teedy
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')