Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
2023-04-25T23:15:09.090
2025-05-30T16:15:34.623
Modified
CVSSv3.1: 8.7 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | dradisframework | dradis | < 4.8.0 | Yes |