gotortc Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
Aug 5, 2024
to the GitHub Advisory Database
•
Updated Aug 5, 2024
Description
Published by the National Vulnerability Database
Apr 4, 2024
Published to the GitHub Advisory Database
Aug 5, 2024
Reviewed
Aug 5, 2024
Last updated
Aug 5, 2024
gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The links page (
links.html
) appends thesrc
GET parameter ([0]
) in all of its links for 1-click previews. The context in whichsrc
is being appended isinnerHTML
([1]
), which will insert the text as HTML. Commit 3b3d5b033aac3a019af64f83dec84f70ed2c8aba contains a patch for the issue.References