Improper Neutralization of Text-Values in Object Version Preview
Description
Published by the National Vulnerability Database
Sep 1, 2021
Reviewed
Sep 1, 2021
Published to the GitHub Advisory Database
Sep 1, 2021
Last updated
Feb 1, 2023
Text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources.
References