Lucene search

K
osvGoogleOSV:GHSA-JP6R-XCJJ-5H7R
HistoryAug 27, 2019 - 5:36 p.m.

Cross-Site Scripting in cyberchef

2019-08-2717:36:32
Google
osv.dev
16

EPSS

0.001

Percentile

42.5%

Versions of cyberchef prior to 8.31.3 are vulnerable to Cross-Site Scripting. In Text Encoding Brute Force the table rows are created by concatenating the value variable unsanitized in the HTML code. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Upgrade to version 8.31.3 or later.

EPSS

0.001

Percentile

42.5%