This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
CVE Sentinel
cve-notifications.bsky.social
did:plc:fmpxu5qaccixyxvvyzsllshl
ID: CVE-2024-54951
CVSS N/A
Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.
#security #infosec #cve-alert
https://nvd.nist.gov/vuln/detail/CVE-2024-54951
2025-02-13T23:16:03.348Z