
An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
As stated on the advisories versions 8.8.x before 8.8.15 patch 30 (update 1) are vulnerable to attacks, the template looks at the following versions:
- "8.8"
- "8.8.6"
- "8.8.7"
- "8.8.8"
- "8.8.9"
- "8.8.10"
- "8.8.11"
- "8.8.12"
- "8.8.15"
nuclei -u https://yourHost.com -t template.yamlUse at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
If you have any questions please do reach out to me via Signal or via email: [email protected].
If you'd like to support my work, feel free to donate via Buy Me a Coffee — your support means a lot and is truly appreciated!