Loading HuntDB...

Stored XSS in AREA tutorials

High
A
Autodesk
Submitted None

Team Summary

Official summary from Autodesk

A stored cross-site scripting (XSS) vulnerability was found on AREA, which could have allowed an attacker to inject malicious JavaScript code when publishing a tutorial. Autodesk has fixed the vulnerability and we thank @who_am_i_ for reporting this issue.

Reported by who_am_i_

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored