Matt Zajork/Journal/CVE-2023-1240 - Cross-Site Scripting in answerdev/answer/CVE-2023-1240 - Cross-Site Scripting in answerdev/answer8 February 2023·1 minTable of ContentsDescriptionReferencesDescription #A stored, DOM-based cross-site scripting vulnerability exists in answer version 1.0.4 within the question tagging functionality.References #https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1240https://huntr.dev/bounties/a24f57a4-22e3-4a17-8227-6a410a11498a/https://nvd.nist.gov/vuln/detail/CVE-2023-1240https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMANSWERDEVANSWERINTERNALSCHEMA-3350600