CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/gchq/CyberChef/issues/544 | patch third party advisory issue tracking |
https://github.com/gchq/CyberChef/issues/539 | third party advisory exploit |
https://github.com/gchq/CyberChef/commit/01f0625d6a177f9c5df9281f12a27c814c2d8bcf | third party advisory patch |
https://github.com/gchq/CyberChef/compare/v8.31.1...v8.31.2 | third party advisory patch |