Skip to content

Stored XSS in budget type

Moderate
trasher published GHSA-m574-f3jw-pwrf Mar 2, 2021

Package

No package listed

Affected versions

< 9.5.4

Patched versions

9.5.4

Description

Impact

New budget type can be defined by user this input is not correctly filtered,to exploit this endpoint attacker need to be authenticated.

Patches

fixed in 9.5.4

Severity

Moderate

CVE ID

CVE-2021-21325

Weaknesses

No CWEs

Credits