usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos prior to 0.9.0 has a feature to upload file and display it, and by uploading a crafted SVG file, an attacker could perform a stored cross-site scripting attack with the image direct link. This was patched in version 0.9.0.
{
"github_reviewed": true,
"github_reviewed_at": "2022-12-27T01:29:44Z",
"nvd_published_at": "2022-12-23T12:15:00Z",
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE"
}