CVE-2024-38521

CVSS V2 None CVSS V3 None
Description
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored XSS in the Inbox. The input is displayed using the `safe` Jinja2 attribute, and thus not sanitized upon display. This issue has been patched in version 0.1.0.
Overview
  • CVE ID
  • CVE-2024-38521
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-28T15:33:21.032Z
  • Last Modified Date
  • 2024-06-28T15:33:21.032Z
References
Reference URL Reference Tags
https://github.com/scidsg/hushline/security/advisories/GHSA-4v8c-r6h2-fhh3 x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-06-29 13:12:08 Added to TrackCVE