First published: Wed Feb 15 2023(Updated: )
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Usememos Memos | ||
go/github.com/usememos/memos | <0.10.4-0.20230211093429-b11d2130a084 | 0.10.4-0.20230211093429-b11d2130a084 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-25978 is medium.
CVE-2022-25978 affects all versions of the package github.com/usememos/memos/server.
CVE-2022-25978 is a Cross-site Scripting (XSS) vulnerability.
CVE-2022-25978 allows malicious actors to introduce links starting with a javascript: scheme.
To fix CVE-2022-25978, update to a version of github.com/usememos/memos/server that includes the necessary checks on external resources.