Publish Time: 2018-01-23 17:25:28 UTC+8
Last Updated: 2018-05-08 18:34:19 UTC+8
Abstract
These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via a susceptible version of Note Station.
Affected Products
Product | Severity | Latest Patch |
---|---|---|
Note Station | Moderate | Upgrade to 2.5.1-0844 or above. |
Mitigation
None
Detail
CVE-2018-8911
CVE-2018-8912
Acknowledgement
Taien Wang (https://www.linkedin.com/in/taienwang/)
Revision History
Revision | Date | Description |
---|---|---|
1 | 2018-01-23 | Initial public release. |
2 | 2018-05-08 | Disclosed vulnerability details. |