Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1536 | All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found. |
Github GHSA |
GHSA-g47h-fgcw-g4ph | Algernon engine and themes vulnerable to Cross-site Scripting |
Thu, 09 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-01-09T20:38:45.687Z
Reserved: 2023-02-20T10:28:48.924Z
Link: CVE-2023-26131
Updated: 2024-08-02T11:39:06.629Z
Status : Modified
Published: 2023-05-31T05:15:10.180
Modified: 2025-01-09T21:15:22.080
Link: CVE-2023-26131
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA