Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7777 | Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts **if** another user opened a link. The attacker could potentially take over the account of the user that clicked the link. The Gotify UI won't natively expose such a malicious link, so an attacker has to get the user to open the malicious link in a context outside of Gotify. The vulnerability has been fixed in version 2.2.2. As a workaround, you can block access to non image files via a reverse proxy in the `./image` directory. |
Github GHSA |
GHSA-xv6x-456v-24xh | gotify/server vulnerable to Cross-site Scripting in the application image file upload |
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-10T18:02:15.686Z
Reserved: 2022-11-28T17:27:19.999Z
Link: CVE-2022-46181
Updated: 2024-08-03T14:31:44.432Z
Status : Modified
Published: 2022-12-29T19:15:08.810
Modified: 2026-06-17T05:11:22.820
Link: CVE-2022-46181
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA