Oxidized Web vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Dec 27, 2022
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Description
Published by the National Vulnerability Database
Dec 27, 2022
Published to the GitHub Advisory Database
Dec 27, 2022
Reviewed
Jan 9, 2023
Last updated
Mar 1, 2024
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file
lib/oxidized/web/views/conf_search.haml
. The manipulation of the argumentto_research
leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.References