CVE-2014-5144
MEDIUMTelescope < 0.9.0 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0057
EPSS Percentile
68.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
telescopeapp/telescope
< 0.9.0
n/a/n/a
Published
Aug 09, 2017
Tracked Since
Feb 18, 2026