VDB
Sign up
MEDIUM5.4

GHSA-cvqr-mwh6-2vc6

Apache Answer: XSS vulnerability when changing personal website

Quick fix

GHSA-cvqr-mwh6-2vc6 — github.com/apache/incubator-answer: upgrade to the fixed version with the command below.

go get github.com/apache/incubator-answer@v1.3.0

Details

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.

XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/apache/incubator-answer
Introduced in: 0Fixed in: 1.3.0
Fixgo get github.com/apache/incubator-answer@v1.3.0

References