Andrew Maltsev

1 exploit Active since Mar 2024
CVE-2020-36827 WRITEUP MEDIUM WRITEUP
XAO::Web < 1.84 - Cross-Site Scripting via JSON Output in Web::Action
The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.
CVSS 5.4