Lucene search

K
osvGoogleOSV:USN-4758-1
HistoryMar 08, 2021 - 7:10 p.m.

golang-1.10, golang-1.14 vulnerability

2021-03-0819:10:40
Google
osv.dev
13
go applications
uploaded content
xss attacks
remote attacker
malicious page

AI Score

5.7

Confidence

High

EPSS

0.006

Percentile

79.0%

It was discovered that Go applications incorrectly handled uploaded content. If
a user were tricked into visiting a malicious page, a remote attacker could
exploit this with a crafted file to conduct cross-site scripting (XSS) attacks.