—
GO-2024-3125
Gouniverse GoLang CMS vulnerable to Cross-site Scripting in github.com/gouniverse/cms
Quick fix
GO-2024-3125 — github.com/gouniverse/cms: upgrade to the fixed version with the command below.
go get github.com/gouniverse/cms@v1.4.1Details
Gouniverse GoLang CMS vulnerable to Cross-site Scripting in github.com/gouniverse/cms
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gouniverse/cms
Introduced in:
0Fixed in: 1.4.1Fix
go get github.com/gouniverse/cms@v1.4.1References
- https://github.com/advisories/GHSA-pv7h-hg6m-82j8[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-8572[ADVISORY]
- https://github.com/gouniverse/cms/commit/3e661cdfb4beeb9fe2ad507cdb8104c0b17d072c[FIX]
- https://github.com/gouniverse/cms/issues/5[REPORT]
- https://github.com/gouniverse/cms/issues/5#issuecomment-2330848731[REPORT]
- https://github.com/gouniverse/cms/releases/tag/v1.4.1[WEB]
- https://vuldb.com/?ctiid.276802[WEB]
- https://vuldb.com/?id.276802[WEB]
- https://vuldb.com/?submit.401896[WEB]