Stored Cross Site Scripting Vulnerability in InvoicePlane by InvoicePlane
CVE-2017-1000239
5.4MEDIUM
What is CVE-2017-1000239?
InvoicePlane version 1.4.10 contains a vulnerability that allows authenticated users to perform a Stored Cross Site Scripting (XSS) attack. Through this vulnerability, attackers can inject malicious client-side scripts that will be executed in the browsers of users visiting the compromised pages, potentially leading to unauthorized access and further exploitation.