Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
| Software | From | Fixed in |
|---|---|---|
| invoiceplane / invoiceplane | 1.6.0-beta | 1.6.0-beta.x |
| invoiceplane / invoiceplane | 1.6.0-beta1 | 1.6.0-beta1.x |
| invoiceplane / invoiceplane | 1.6.0-beta2 | 1.6.0-beta2.x |
| invoiceplane / invoiceplane | 1.6.0-beta3 | 1.6.0-beta3.x |
| invoiceplane / invoiceplane | 1.6.0 | 1.6.0.x |