Beveiligingsadvies

CVE-2023-29014

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-04-06 19:03:19
Laatst bijgewerkt 2025-02-10 16:12:23
Toegewezen door GitHub_M
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser. The vulnerability has been fixed in version 23.03.