Server side cross-site scripting In gogs.io/gogs
Description
Cross-site Scripting in Gogs Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.8 allows remote attackers to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.5.8 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8.