GHSA-7j6x-42mm-p7jm
Dashboard / Vulnerabilities / GHSA-7j6x-42mm-p7jm
GHSA-7j6x-42mm-p7jm
Summary: Zinc Cross-site Scripting vulnerability
Details: In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-32172, https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d, https://github.com/zincsearch/zincsearch/commit/3376c248bade163430f9347742428f0a82cd322d, https://www.mend.io/vulnerability-database/CVE-2022-32172
Affected packages
Package
Name: github.com/zincsearch/zincsearch
Purl: pkg:golang/github.com/zincsearch/zincsearch
Affected ranges
Type: SEMVER
Events:
