ZeroHour

CVE-2024-2692

PoC
CVSS 3.1
9.0 critical
EPSS
<1%p52
Published
()
Modified
Description

SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

Vendors
b3log
Products
siyuan
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.