Skip to content

XSS vulnerability caused by unvalidated URL parameters

Moderate
DIYgod published GHSA-32gr-4cq6-5w5q Feb 28, 2023

Package

rsshub

Affected versions

before c910c4d

Patched versions

c910c4d

Description

Impact

When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code.

Users who access the deliberately constructed URL are affected.

Patches

This vulnerability was fixed in version c910c4d. Please upgrade to this or a later version.

Workarounds

No.

Severity

Moderate

CVE ID

CVE-2023-26491

Weaknesses

No CWEs

Credits