Skip to content
This repository has been archived by the owner on May 7, 2024. It is now read-only.

CVE-2023-39791 #829

Open
AnduriCaser opened this issue Feb 13, 2024 · 0 comments
Open

CVE-2023-39791 #829

AnduriCaser opened this issue Feb 13, 2024 · 0 comments

Comments

@AnduriCaser
Copy link

I found an Stored XSS in Konga Dashboard v0.14.9. This type of XSS leads to account takeover admin accounts. I explained the details in the link below.

https://docs.google.com/document/d/1v7k1lYxIvMc6Jgxea1-blCJ2FV0XBl3z8hSrbfYaufk/edit?usp=sharing

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant