Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8jh-vcjh-fx2w

Опубликовано: 23 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

usememos/memos vulnerable to stored cross-site scripting (XSS)

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos prior to 0.9.0 has a feature to upload file and display it, and by uploading a crafted SVG file, an attacker could perform a stored cross-site scripting attack with the image direct link. This was patched in version 0.9.0.

Пакеты

Наименование

github.com/usememos/memos

go
Затронутые версииВерсия исправления

< 0.9.0

0.9.0

EPSS

Процентиль: 49%
0.00261
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

EPSS

Процентиль: 49%
0.00261
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79