Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 Go

Algernon engine and themes vulnerable to Cross-site Scripting

GHSA-g47h-fgcw-g4ph · CVE-2023-26131

Published · Modified

Description

All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.

Ready to move

Start Securing

Free, no credit card | First findings in minutes