Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored XSS in the Inbox. The input is displayed using the `safe` Jinja2 attribute, and thus not sanitized upon display. This issue has been patched in version 0.1.0.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hushline
Hushline hush Line |
|
CPEs | cpe:2.3:a:hushline:hush_line:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hushline
Hushline hush Line |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-28T15:33:21.032Z
Updated: 2024-08-02T04:12:25.140Z
Reserved: 2024-06-18T16:37:02.728Z
Link: CVE-2024-38521
Vulnrichment
Updated: 2024-08-02T04:12:25.140Z
NVD
Status : Modified
Published: 2024-06-28T16:15:04.577
Modified: 2024-11-21T09:26:10.227
Link: CVE-2024-38521
Redhat
No data.