Vulnerability GHSA-jp6r-xcjj-5h7r
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 years ago
August 27, 2019 at 05:36 PM UTC
Cross-Site Scripting in cyberchef
4.0.0 - 8.31.1
4.0.0 - 8.31.1
Summary
Cross-Site Scripting in cyberchef
Details
Versions of cyberchef prior to 8.31.3 are vulnerable to Cross-Site Scripting. In Text Encoding Brute Force the table rows are created by concatenating the value variable unsanitized in the HTML code. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
Recommendation
Upgrade to version 8.31.3 or later.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 days ago
CyberChef: Prototype pollution in Series Chart operation
4.0.0 - 11.1.0 GHSA-fx6f-382r-j72c
4.0.0 - 11.1.0 GHSA-fx6f-382r-j72c
High Risk
5 months ago
CyberChef has a Cross-site Scripting issue
4.0.0 - 10.24.0 GHSA-h4hv-92pp-pcjg
4.0.0 - 10.24.0 GHSA-h4hv-92pp-pcjg
Impacted packages
Timeline
Published
7 years ago
August 27, 2019 at 05:36 PM UTC
Fixed (8.31.3)
7 years ago
May 09, 2019 at 04:16 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:01 AM UTC