Skip to content

Conversation

@nerrorsec
Copy link

The description of CVE-2024-8366 contains <script>alert(1)</script> which gets executed when CVE summary is viewed. This PR prevents the payloads in description from being executed by escaping the description.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants