Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/usd-2020-0048/ | third party advisory exploit |
https://github.com/gophish/gophish/commit/90fed5a575628b89eaf941e1627b49e0f3693812 | third party advisory patch |