Beveiligingsadvies
CVE-2017-18217
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.