Inline attribute values were not processed.
High severity
GitHub Reviewed
Published
Oct 19, 2020
in
orchidsoftware/platform
•
Updated Jan 9, 2023
Description
Reviewed
Oct 19, 2020
Published to the GitHub Advisory Database
Oct 19, 2020
Last updated
Jan 9, 2023
Impact
Inline attributes have not been processed escape.
If the data that came from users was not processed, then an XSS vulnerability is possible
Patches
Fixed in 9.4.4
References