PT-2024-22795 · Gotortc · Gotortc

Jorge Rosillo

+1

·

Published

2024-04-04

·

Updated

2024-08-06

·

CVE-2024-29191

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions gotortc versions 1.8.5 and prior
Description The issue is related to DOM-based cross-site scripting. The links page (links.html) appends the src GET parameter ([0]) in all of its links for 1-click previews. The context in which src is being appended is innerHTML ([1]), which will insert the text as HTML.
Recommendations For versions 1.8.5 and prior, apply the patch from commit 3b3d5b033aac3a019af64f83dec84f70ed2c8aba to resolve the issue. As a temporary workaround, consider restricting the use of the links.html page or disabling the 1-click preview feature until the patch is applied. Avoid using the src parameter in the affected links until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-29191
GHSA-WV8X-3W6R-6H7V
GO-2024-3055

Affected Products

Gotortc