Stored Cross-Site Scripting in tianma-static
Moderate severity
GitHub Reviewed
Published
Nov 6, 2018
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Nov 6, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
All versions of
tianma-static
are vulnerable to stored cross-site scripting (XSS). The vulnerability is exploitable if a user can control the name of a file that is served bytianma-static
Recommendation
As no fix is available for this vulnerability at this time it is our recommendation to use another static file server.
References