CVE-2019-17488 by Fred · 10/10/2019 b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. Date published : 2019-10-10 https://github.com/b3log/symphony/issues/970 Share this: Share on X (Opens in new window) X Share on Bluesky (Opens in new window) Bluesky Share on Facebook (Opens in new window) Facebook Share on LinkedIn (Opens in new window) LinkedIn Share on Threads (Opens in new window) Threads Share on Mastodon (Opens in new window) Mastodon Similar