MEDIUM5.4
GHSA-cvqr-mwh6-2vc6
Apache Answer: XSS vulnerability when changing personal website
Quick fix
GHSA-cvqr-mwh6-2vc6 — github.com/apache/incubator-answer: upgrade to the fixed version with the command below.
go get github.com/apache/incubator-answer@v1.3.0Details
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/apache/incubator-answer
Introduced in:
0Fixed in: 1.3.0Fix
go get github.com/apache/incubator-answer@v1.3.0