Vulnerability Description
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Algernon Project | Algernon | All versions |
Related Weaknesses (CWE)
References
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMXYPROTOALGERNONENGINE-3312111ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMXYPROTOALGERNONTHEMES-3312112ExploitThird Party Advisory
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://github.com/xyproto/algernon/blob/aab484608651852d02a8a93f40baf53ed93e639Broken Link
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMXYPROTOALGERNONENGINE-3312111ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMXYPROTOALGERNONTHEMES-3312112ExploitThird Party Advisory
FAQ
What is CVE-2023-26131?
CVE-2023-26131 is a vulnerability with a CVSS score of 5.4 (MEDIUM). All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filena...
How severe is CVE-2023-26131?
CVE-2023-26131 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26131?
Check the references section above for vendor advisories and patch information. Affected products include: Algernon Project Algernon.