From 6eb363e48eb6883cd9b7d4cc79a0f22b50b68b3c Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 29 May 2024 13:06:26 +0000
Subject: [PATCH] Publish GHSA-g6f5-4w43-2x63
---
.../GHSA-g6f5-4w43-2x63.json | 65 +++++++++++++++++++
1 file changed, 65 insertions(+)
create mode 100644 advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json
diff --git a/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json b/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json
new file mode 100644
index 00000000000..8380dfecd87
--- /dev/null
+++ b/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g6f5-4w43-2x63",
+ "modified": "2024-05-29T13:04:32Z",
+ "published": "2024-05-29T13:04:32Z",
+ "aliases": [
+
+ ],
+ "summary": "ScnSocialAuth Cross-site Scripting vulnerability in login redirect param",
+ "details": "ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700\n\n### Affected versions\nAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700\n\n### Exploits\nBecause of missing escaping of the URL param redirect a XSS attack is possible.\nFor example: Setting the redirect param to `\">GitHub.com