From 6eb363e48eb6883cd9b7d4cc79a0f22b50b68b3c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 May 2024 13:06:26 +0000 Subject: [PATCH] Publish GHSA-g6f5-4w43-2x63 --- .../GHSA-g6f5-4w43-2x63.json | 65 +++++++++++++++++++ 1 file changed, 65 insertions(+) create mode 100644 advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json diff --git a/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json b/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json new file mode 100644 index 00000000000..8380dfecd87 --- /dev/null +++ b/advisories/github-reviewed/2024/05/GHSA-g6f5-4w43-2x63/GHSA-g6f5-4w43-2x63.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6f5-4w43-2x63", + "modified": "2024-05-29T13:04:32Z", + "published": "2024-05-29T13:04:32Z", + "aliases": [ + + ], + "summary": "ScnSocialAuth Cross-site Scripting vulnerability in login redirect param", + "details": "ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700\n\n### Affected versions\nAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700\n\n### Exploits\nBecause of missing escaping of the URL param redirect a XSS attack is possible.\nFor example: Setting the redirect param to `\">GitHub.com