eval.blog

Code Execution via Cross Site Scripting in Tagspaces (A file manager)

Reported a code execution via cross site scripting in TagSpaces. The XSS is used to escape the sandbox of electron to gain code execution in TagSpaces.

References: