VDB
Sign up
MEDIUM6.1

GHSA-622w-995c-3c3h

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments

Quick fix

GHSA-622w-995c-3c3h — io.goobi.viewer:viewer-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-core

Details

### Impact A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment.

### Patches The vulnerability has been fixed in version 23.03

If you have any questions or comments about this advisory: * Email us at [support@intranda.com](mailto:support@intranda.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.goobi.viewer:viewer-core
Introduced in: 0Fixed in: 23.03
Fix# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-core

References