GHSA-7v7g-9vx6-vcg2
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter
Quick fix
GHSA-7v7g-9vx6-vcg2 — io.goobi.viewer:viewer-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-coreDetails
### Impact A reflected cross-site scripting vulnerability has been identified in Goobi viewer core when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser.
### Patches The vulnerability has been fixed in version 23.03
### Credits We would like to thank [RUS-CERT](https://cert.uni-stuttgart.de/) for reporting this issues.
If you have any questions or comments about this advisory: * Email us at [support@intranda.com](mailto:support@intranda.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 23.03# pom.xml: bump <version>23.03</version> for io.goobi.viewer:viewer-core