blob: fa2e6d1f9ffb512268c3154971d6913cbc8632c5 [file] [log] [blame]
id: GO-2025-3585
modules:
- module: github.com/beego/beego
vulnerable_at: 1.12.14
- module: github.com/beego/beego/v2
versions:
- fixed: 2.3.6
vulnerable_at: 2.3.5
packages:
- package: github.com/beego/beego/v2/server/web
symbols:
- renderFormField
summary: |-
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to
Unescaped User Input in github.com/beego/beego
cves:
- CVE-2025-30223
ghsas:
- GHSA-2j42-h78h-q4fg
references:
- advisory: https://github.com/beego/beego/security/advisories/GHSA-2j42-h78h-q4fg
- fix: https://github.com/beego/beego/commit/939bb18c66406466715ddadd25dd9ffa6f169e25
notes:
- No patched version exists for github.com/beego/beego
source:
id: GHSA-2j42-h78h-q4fg
created: 2025-03-31T13:59:23.508609-04:00
review_status: REVIEWED