Impact
Users with component view access could be impacted by an unescaped notes column.
Patches
This was patched in 28f493d, and is fixed in v8.4.1 or greater.
Workarounds
No.
References
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N = 6.1 (Medium)
CWE-79: Improper Neutralization of Input During Web Page Generation (Stored XSS)
Impact
Users with component view access could be impacted by an unescaped
notescolumn.Patches
This was patched in 28f493d, and is fixed in v8.4.1 or greater.
Workarounds
No.
References
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N = 6.1 (Medium)
CWE-79: Improper Neutralization of Input During Web Page Generation (Stored XSS)