Description
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.
Published: 2024-01-04
Score: 6.1 Medium
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1419 govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.
Github GHSA Github GHSA GHSA-x2xw-hw8g-6773 govuk_tech_docs vulnerable to unescaped HTML on search results page
History

Sat, 29 Nov 2025 02:00:00 +0000

Type Values Removed Values Added
Description govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.

Wed, 04 Jun 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Gov.uk Govuk Tech Docs
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-29T01:17:53.478Z

Reserved: 2024-01-04T18:44:53.107Z

Link: CVE-2024-22048

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.627Z

cve-icon NVD

Status : Modified

Published: 2024-01-04T21:15:09.940

Modified: 2026-06-17T07:10:36.673

Link: CVE-2024-22048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses