Beveiligingsadvies

CVE-2024-50810

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-08 00:00:00
Laatst bijgewerkt 2024-11-20 23:02:23
Toegewezen door mitre
CVSS-score 5.4
Status PUBLISHED

Beschrijving

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.