Description
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser. The vulnerability has been fixed in version 23.03.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1232 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser. The vulnerability has been fixed in version 23.03. |
Github GHSA |
GHSA-7v7g-9vx6-vcg2 | Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter |
References
History
Mon, 10 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-10T16:12:23.454Z
Reserved: 2023-03-29T17:39:16.143Z
Link: CVE-2023-29014
Updated: 2024-08-02T14:00:14.389Z
Status : Modified
Published: 2023-04-06T20:15:08.557
Modified: 2024-11-21T07:56:23.790
Link: CVE-2023-29014
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA