Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3584 | LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability in the `Referer` HTTP header. The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response. Commit 7ecb839df9358d21f64cdbff5b2536af25a77de1 contains a patch for the issue. |
Github GHSA |
GHSA-ggwq-xc72-33r3 | LGSL has a reflected XSS at /lgsl_files/lgsl_list.php |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 30 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability in the `Referer` HTTP header. The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response. Commit 7ecb839df9358d21f64cdbff5b2536af25a77de1 contains a patch for the issue. | |
| Title | LGSL has a reflected XSS at /lgsl_files/lgsl_list.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-30T17:22:50.748Z
Reserved: 2024-12-26T22:34:35.564Z
Link: CVE-2024-56517
Updated: 2024-12-30T17:22:41.315Z
Status : Received
Published: 2024-12-30T17:15:09.840
Modified: 2024-12-30T17:15:09.840
Link: CVE-2024-56517
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA