From fb631a12f6fc8ff8824cf800f6d5c7055c4b5dd2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Jun 2025 06:28:43 +0000 Subject: [PATCH] Publish Advisories GHSA-4xg4-54hm-9j77 GHSA-95rc-wc32-gm53 --- .../GHSA-4xg4-54hm-9j77.json | 85 ++++++++++++++++++ .../GHSA-95rc-wc32-gm53.json | 89 +++++++++++++++++++ 2 files changed, 174 insertions(+) create mode 100644 advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json create mode 100644 advisories/github-reviewed/2025/06/GHSA-95rc-wc32-gm53/GHSA-95rc-wc32-gm53.json diff --git a/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json b/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json new file mode 100644 index 00000000000..a880c6083c8 --- /dev/null +++ b/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xg4-54hm-9j77", + "modified": "2025-06-03T06:27:28Z", + "published": "2025-06-03T06:27:28Z", + "aliases": [ + "CVE-2025-48495" + ], + "summary": "Gokapi has stored XSS vulnerability in friendly name for API keys", + "details": "### Impact\n\nBy renaming the friendly name of an API key, an authenticated user could inject JS into the API key overview, which would also be executed when another user clicks on his API tab.\nWith the affected versions