Vulnerability Report: GO-2023-1566
- CVE-2022-25978, GHSA-9w8x-5hv5-r6gw
- Affects: github.com/usememos/memos
- Published: Feb 15, 2023
- Modified: May 20, 2024
A malicious actor can introduce links starting with a "javascript:" scheme due to insufficient checks on external resources. This can be used as a part of Cross-site Scripting (XSS) attack.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.10.4-0.20230211093429-b11d2130a084
Aliases
References
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMUSEMEMOSMEMOSSERVER-3319070
- https://github.com/usememos/memos/commit/b11d2130a084385eb65c3761a3c841ebe9f81ae8
- https://github.com/usememos/memos/issues/1026
- https://vuln.go.dev/ID/GO-2023-1566.json
Credits
- Kahla
Feedback
See anything missing or incorrect?
Suggest an edit to this report.