PT-2023-12595 · Nim+2 · Nim+2
Araq
·
Published
2023-01-13
·
Updated
2023-06-03
·
CVE-2021-46872
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nim versions prior to 1.6.2
NimForum versions prior to 2.2.0
Description
An issue in the RST module of the Nim language stdlib allows the javascript: URI scheme, potentially leading to XSS in some applications.
Recommendations
For Nim versions prior to 1.6.2, update to version 1.6.2 or later to resolve the issue.
For NimForum versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the RST module in the Nim language stdlib until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Nim
Nimforum