CERTCC / VINCE

VINCE is the Vulnerability Information and Coordination Environment developed and used by the CERT Coordination Center to improve coordinated vulnerability disclosure. VINCE is a Python-based web platform.

Home Page:https://kb.cert.org/vince/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

An HTML Injection vulnerability when email with Subject is rendered.

sei-vsarvepalli opened this issue · comments

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. A remote user can inject arbitrary HTML via a crafted email with HTML content in the Subject field. This issue was reported by Rapid7 researcher Nick Sanzotta.

Resolved issue #56 - thanks to @NickSanzotta