Loading HuntDB...

GHSA-44qv-5wxp-8xqv

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

Related CVEs

Key Information

GHSA ID
GHSA-44qv-5wxp-8xqv
Published
July 7, 2022 12:00 AM
Last Modified
July 15, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.