Description
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment. The vulnerability has been fixed in version 23.03.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1210 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment. The vulnerability has been fixed in version 23.03. |
Github GHSA |
GHSA-622w-995c-3c3h | Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments |
References
History
Mon, 10 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-10T16:11:59.823Z
Reserved: 2023-03-29T17:39:16.143Z
Link: CVE-2023-29015
Updated: 2024-08-02T14:00:14.382Z
Status : Modified
Published: 2023-04-06T20:15:08.613
Modified: 2024-11-21T07:56:23.910
Link: CVE-2023-29015
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA