GHSA-4fgv-8448-gf82
Dashboard / Vulnerabilities / GHSA-4fgv-8448-gf82
GHSA-4fgv-8448-gf82
Summary: Zinc Cross-site Scripting vulnerability
Details: In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to access the user’s credentials.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-32171, https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d, https://github.com/zincsearch/zincsearch/commit/3376c248bade163430f9347742428f0a82cd322d, https://www.mend.io/vulnerability-database/CVE-2022-32171
Affected packages
Package
Name: github.com/zincsearch/zincsearch
Purl: pkg:golang/github.com/zincsearch/zincsearch
Affected ranges
Type: SEMVER
Events:
