Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/usd-2020-0050/ | third party advisory exploit |
https://github.com/gophish/gophish/commit/4e9b94b641755f359542b246cc0c555fa3bc6715 | third party advisory patch |
https://github.com/gophish/gophish/releases/tag/v0.11.0 | third party advisory |