CVE-2017-18217
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
MEDIUM · CVSS 6.1
EPSS 0.0034
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0