Cross-site Scripting in OctoPrint
High severity
GitHub Reviewed
Published
May 19, 2022
to the GitHub Advisory Database
•
Updated Oct 8, 2024
Description
Published by the National Vulnerability Database
May 18, 2022
Published to the GitHub Advisory Database
May 19, 2022
Reviewed
May 25, 2022
Last updated
Oct 8, 2024
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. The login endpoint allows for javascript injection which may lead to account takeover in a phishing scenario.
References