GHSA-vxh3-mvv7-265j
MODERATECVE-2019-1020003A Cross-Site Scripting (XSS) vulnerability was discovered when rendering JSON for a record in the administration interface. The vulnerability could be exploited by e.g. a user who had access to upload a new record, that an admin user would then later view in the admin interface.
- Affected
- >= 1.2.0, < 1.2.2, = 1.1.0, < 1.0.2
- Fixed in
- 1.2.2
- Weakness
- CWE-79
- Published
- 2019-07-16
- Source
- github