GHSA-r8f4-hv23-6qp6
HIGHCVE-2023-32193A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.
- Affected
- < 0.0.0-20240207153100-3bb70b772b52
- Fixed in
- 0.0.0-20240207153100-3bb70b772b52
- Weakness
- CWE-80
- Published
- 2024-02-08
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference