Security Advisory
CVE-2019-18209
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.