KeystoneJS 4.0.0-beta.5 Unauthenticated CSV Injection

Discussion in 'News Aggregator' started by Packet Storm, 25 Oct 2017.

  1. Packet Storm

    Packet Storm Guest

    KeystoneJS version 4.0.0-beta.5 suffers from an unauthenticated CSV injection vulnerability in admin/server/api/download.js and lib/list/getCSVData.js.

    Continue reading...
     

Share This Page

Loading...