← Back to CVE List

CVE-2018-11044

Published: 2018-07-24T19:29Z
Last Modified: 2024-11-21T03:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt