You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/mlogclub/bbs-go
vulnerable_at: 1.0.5
packages:
- package: n/a
description: |-
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before
allows a remote attacker to execute arbitrary code via a crafted payload to the
announcements parameter in the settings function.
cves:
- CVE-2023-36223
references:
- web: http://bbs-go.com
- web: https://github.com/mlogclub/bbs-go
- report: https://github.com/mlogclub/bbs-go/issues/208
The text was updated successfully, but these errors were encountered:
CVE-2023-36223 references github.com/mlogclub/bbs-go, which may be a Go module.
Description:
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: