hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/Hopetree/izone/issues/289 |
|
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 20 Nov 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tendcode
Tendcode izone |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:tendcode:izone:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tendcode
Tendcode izone |
|
| Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-08T00:00:00
Updated: 2024-11-20T23:02:23.484Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-50810
Updated: 2024-11-20T23:02:14.821Z
Status : Awaiting Analysis
Published: 2024-11-08T19:15:05.877
Modified: 2024-11-21T09:44:56.153
Link: CVE-2024-50810
No data.
ReportizFlow