GHSA-94cc-xjxr-pwvf
LOWCVE-2024-38364In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user's browser may execute any embedded JavaScript. If that embedded JavaScript is malicious, there is a risk of an XSS attack.
- Affected
- >= 7.0, < 7.6.2
- Fixed in
- 7.6.2
- Weakness
- CWE-79
- Published
- 2024-06-25
- Source
- github