Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Passer6Yo

#44075de 53,630
6.1CVSS total
Vulnerabilidades · 1
PT-2018-14907
6.1
2018-11-15
Valine · Valine · CVE-2018-19289
**Name of the Vulnerable Software and Affected Versions** Valine version 1.3.3 **Description** An issue in Valine allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file. **Recommendations** For Valine version 1.3.3, consider disabling the ability to embed files, especially .pdf files, until a patch is available to prevent HTML injection and potential JavaScript execution.