CVE-2020-15156

CVE-2020-15156

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

Source: CVE-2020-15156

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다