Логотип exploitDog
bind:CVE-2025-30223
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30223

Количество 2

Количество 2

nvd логотип

CVE-2025-30223

10 месяцев назад

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due to improper HTML escaping of user-controlled data. This vulnerability allows attackers to inject malicious JavaScript code that executes in victims' browsers, potentially leading to session hijacking, credential theft, or account takeover. The vulnerability affects any application using Beego's RenderForm() function with user-provided data. Since it is a high-level function generating an entire form markup, many developers would assume it automatically escapes attributes (the way most frameworks do). This vulnerability is fixed in 2.3.6.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2j42-h78h-q4fg

10 месяцев назад

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30223

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due to improper HTML escaping of user-controlled data. This vulnerability allows attackers to inject malicious JavaScript code that executes in victims' browsers, potentially leading to session hijacking, credential theft, or account takeover. The vulnerability affects any application using Beego's RenderForm() function with user-provided data. Since it is a high-level function generating an entire form markup, many developers would assume it automatically escapes attributes (the way most frameworks do). This vulnerability is fixed in 2.3.6.

CVSS3: 9.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2j42-h78h-q4fg

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу