Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 PyPI

Koji Cross-site Scripting

GHSA-g2vg-8hfg-79vj · CVE-2024-9427

Published · Modified

Description

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code.

Ready to move

Start Securing

Free, no credit card | First findings in minutes