This repository was archived by the owner on Mar 14, 2023. It is now read-only.
XSS in title construction
Package
app.py
(python)
Affected versions
before 2b93b46ed682c34bc6707e71d3786ce858b98983
Patched versions
2b93b46ed682c34bc6707e71d3786ce858b98983
Impact
A maliciously crafted configuration file could cause an XSS in the page title. This requires access to the webserver.
Patches
https://github.com/MirahezeBots/mirahezebots.org/commit/2b93b46ed682c34bc6707e71d3786ce858b98983.patch
Workarounds
Replace
with
and add 'escape' to the 'from Flask import' list
References
https://phab.mirahezebots.org/T181
For more information
If you have any questions or comments about this advisory: