PT-2026-81282 · Ech0 · Ech0
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.7.3
Description
A stored cross-site scripting issue exists in the public RSS feed. The system fails to perform HTML escaping on tag names and markdown content. This allows attackers with admin privileges to inject malicious tag names or raw HTML into echo content, which then executes as JavaScript in RSS readers that render HTML-type summaries, impacting other users and anonymous subscribers.
Recommendations
Update to version 4.7.3 or later.
Exploit
Fix
XSS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ech0