Skip to content

Cross-site Scripting (XSS) via insufficient URL encoding

Moderate
P0cas published GHSA-mvcf-pxcj-h4qp Jan 3, 2022

Package

No package listed

Affected versions

1.46.0, 1.45.13

Patched versions

1.46.1

Description

Impact

Because double-quotes are not URL-encoded, attackers can escape HTML tags and inject script tags. An attacker could run a script in the victim's browser, leading to user account takeover

Patches

https://github.com/openwhyd/openwhyd/pull/524/files

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits