Stored XSS in AREA tutorials
High
A
Autodesk
Submitted None
Team Summary
Official summary from Autodesk
A stored cross-site scripting (XSS) vulnerability was found on AREA, which could have allowed an attacker to inject malicious JavaScript code when publishing a tutorial. Autodesk has fixed the vulnerability and we thank @who_am_i_ for reporting this issue.
Actions:
Reported by
who_am_i_
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored