GHSA-hmm7-6ph9-8jf2
HIGHCVE-2023-29508A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights.
- Affected
- >= 13.10.10, < 13.10.11, >= 14.4, < 14.4.7, >= 14.9, < 14.10
- Fixed in
- 13.10.11
- Weakness
- CWE-79
- Published
- 2023-04-12
- Source
- github