Security Advisory

CVE-2023-26131

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-05-31 05:00:01
Last updated 2025-01-09 20:38:45
Assigner snyk
State PUBLISHED

Description

All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.