mainly server (selfhosted)
Allows unathenticated user to create administrative user account.
PoC: https://github.com/Chocapikk/CVE-2023-22515arrow-up-right
Nuclei: https://templates.nuclei.sh/public/CVE-2023-22515arrow-up-right
Check for OpenID handling
XSS/HTML injection in macros/plugins (such as render HTML)
Last updated 2 years ago