The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment. The vulnerability has been fixed in version 23.03.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-06T19:03:23.713Z

Updated: 2024-08-02T14:00:14.382Z

Reserved: 2023-03-29T17:39:16.143Z

Link: CVE-2023-29015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-06T20:15:08.613

Modified: 2023-04-13T13:56:00.513

Link: CVE-2023-29015

cve-icon Redhat

No data.