← voltar
CVE-2025-53941

Hollo renders posts received with form elements and allows submission

CVSS 6.1 MEDIUMEPSS 0.2%CWE-79
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
fedify-dev · hollo

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →