This commit is contained in:
CVE Team 2018-01-02 19:18:19 -05:00
commit 52e1ca5f62
No known key found for this signature in database
GPG Key ID: 3504EC0FB4B2FE56

View File

@ -0,0 +1 @@
{"data_version": "4.0","references": {"reference_data": [{"url": "https://github.com/invoiceninja/invoiceninja/issues/1727"}]},"description": {"description_data": [{"lang": "eng","value": "Invoiceninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code. "}]},"data_type": "CVE","affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "<= invoiceninja v3.8.1"}]},"product_name": "invoiceninja"}]},"vendor_name": "invoiceninja"}]}},"CVE_data_meta": {"DATE_ASSIGNED": "2017-12-29","ID": "CVE-2017-1000466","ASSIGNER": "kurt@seifried.org","REQUESTER": "sajeeb.lohani@bulletproof.sh"},"data_format": "MITRE","problemtype": {"problemtype_data": [{"description": [{"lang": "eng","value": "CWE-79"}]}]}}