blob: d9945380b9b393e6d64b159937793847f8f2f4ed [file] [log] [blame]
id: GO-2023-1619
modules:
- module: github.com/answerdev/answer
versions:
- fixed: 1.0.6
vulnerable_at: 1.0.5
summary: Answer vulnerable to Cross-site Scripting in github.com/answerdev/answer
cves:
- CVE-2023-1242
ghsas:
- GHSA-qrwm-xqfr-4vhv
references:
- advisory: https://github.com/advisories/GHSA-qrwm-xqfr-4vhv
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-1242
- fix: https://github.com/answerdev/answer/commit/90bfa0dcc7b49482f1d1e31aee3ab073f3c13dd9
- web: https://huntr.dev/bounties/71c24c5e-ceb2-45cf-bda7-fa195d37e289
source:
id: GHSA-qrwm-xqfr-4vhv
created: 2024-08-20T11:35:33.815946-04:00
review_status: UNREVIEWED
unexcluded: NOT_IMPORTABLE