An authenticated attacker can upload a specially crafted SVG file containing JavaScript code to Memos versions prior to 0.25.0, leading to a stored cross-site scripting (XSS) vulnerability.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view