mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
767 B
Markdown
18 lines
767 B
Markdown
### [CVE-2023-46475](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46475)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/elementalSec/CVE-Disclosures/blob/main/ZentaoPMS/CVE-2023-46475/CVE-2023-46475%20-%20Cross-Site%20Scripting%20(Stored).md
|
|
|
|
#### Github
|
|
- https://github.com/elementalSec/CVE-Disclosures
|
|
|