Launch Week Day 1: Announcing Security Design Review
NONE 0.0 NuGet

Possible injection of HTML into user invite mails

GHSA-xxc6-35r7-796w · CVE-2023-38694

Published · Modified

Description

Impact

A user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended.

Explanation of the vulnerability

A person with access to the backoffice and the "users" section could send a user invite and inject HTML code into the invite message.

Ready to move

Start Securing

Free, no credit card | First findings in minutes