Fossil 2.18 on Windows allows attackers to cause a denial...
Moderate severity
Unreviewed
Published
Jul 29, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jul 28, 2022
Published to the GitHub Advisory Database
Jul 29, 2022
Last updated
Jan 27, 2023
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.
References