3 results (0.002 seconds)

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 0

16 Jul 2024 — Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated user can create a document containing a malicious JavaScript payload. When other users view this document, the malicious Javascript can execute in the origin of Outline. Outline includes CSP rules to prevent third-party code execution, however in the case of self-hosting and having your file ... • https://github.com/outline/outline/security/advisories/GHSA-888c-mvg8-v6wh • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 1

07 Jul 2023 — Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1. • https://github.com/outline/outline/commit/9431df45c210e85b77cd27f2ffaf0358b837afa3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 1

07 Jul 2022 — Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. Una vulnerabilidad de tipo Cross-site Scripting (XSS) - Almacenado en el repositorio de Github outline/outline versiones anteriores a v0.64.4 • https://github.com/outline/outline/commit/85657b7340cdeaa696034f294489df8d6a4914d3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •