MEDIUM6.1
GHSA-2r9r-8fcg-m38g
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames
Quick fix
GHSA-2r9r-8fcg-m38g — io.goobi.viewer:viewer-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-coreDetails
### Impact A cross-site scripting vulnerability has been identified in Goobi viewer core when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's nickname, resulting in the execution in the user's browser when displaying the nickname on certain pages.
### Patches The vulnerability has been fixed in version 23.03
If you have any questions or comments about this advisory: * Email us at [support@intranda.com](mailto:support@intranda.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/io.goobi.viewer:viewer-core
Introduced in:
0Fixed in: 23.03Fix
# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-core