The vulnerability exists due to insufficient sanitization of user-supplied data in the Asciidoctor render. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
This Cyber News was published on www.tenable.com. Publication date: Thu, 23 Jan 2025 23:11:02 +0000