Skip to content

XSS vulnerability with bot pages

Moderate
carolinaisslaying published GHSA-jfm2-c4h4-4wm6 Jun 27, 2020

Package

No package listed

Affected versions

< 5.0.3-Release

Patched versions

5.0.3-Release

Description

Impact

Anyone who visits a bot on the site that has things such as on* attributes.

Patches

The problem is patched in version 5.0.3-Release.

Workarounds

Go through the bots route and update the filtering to match the filters we have created in the htmlReference.json file.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits