Cross-site Scripting in showdoc/showdoc
Critical severity
GitHub Reviewed
Published
Mar 15, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 14, 2022
Published to the GitHub Advisory Database
Mar 15, 2022
Reviewed
Mar 15, 2022
Last updated
Jan 27, 2023
ShowDoc is a tool greatly applicable for an IT team to share documents online. showdoc/showdoc allows .properties files to upload which lead to stored XSS in versions prior to 2.10.4. This allows attackers to execute malicious scripts in the user's browser. This issue was patched in version 2.10.4. There is currently no known workaround.
References