Alist reflected Cross-Site Scripting vulnerability in github.com/alist-org/alist
Alist reflected Cross-Site Scripting vulnerability in github.com/alist-org/alist
02 / AFFECTED SOFTWARE
Affected packages
87 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.
Alist reflected Cross-Site Scripting vulnerability in github.com/alist-org/alist
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47067.json
- https://github.com/alist-org/alist/commit/6100647310594868e931f3de1188ddd8bde93b78
- https://nvd.nist.gov/vuln/detail/CVE-2024-47067
- https://securitylab.github.com/advisories/GHSL-2023-220_Alist/
- https://github.com/advisories/GHSA-8pph-gfhp-w226
- https://securitylab.github.com/advisories/GHSL-2023-220_Alist
- https://github.com/alist-org/alist