mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 12:37:41 +02:00
874 B
874 B
CVE-2021-28162
Description
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
POC
Reference
- https://github.com/eclipse-theia/theia/issues/7283
- https://github.com/eclipse-theia/theia/issues/7283