Security Advisory
CVE-2018-19289
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.