CVE-2022-25978: XSS
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
Other sources
All versions of the package github.com/usememos/memos/server prior to 0.11.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25978?
The severity of CVE-2022-25978 is medium.
How does CVE-2022-25978 affect the package github.com/usememos/memos/server?
CVE-2022-25978 affects all versions of the package github.com/usememos/memos/server.
What is the vulnerability type of CVE-2022-25978?
CVE-2022-25978 is a Cross-site Scripting (XSS) vulnerability.
What are the potential impacts of CVE-2022-25978?
CVE-2022-25978 allows malicious actors to introduce links starting with a javascript: scheme.
How can I fix CVE-2022-25978?
To fix CVE-2022-25978, update to a version of github.com/usememos/memos/server that includes the necessary checks on external resources.