GHSA-6gf5-c898-7rxp
CRITICALCVE-2023-32070HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax.
- Affected
- <= 3.0-milestone-2
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2023-05-11
- Source
- github