Back

MEDIUM

Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter

Published Apr 6, 2023

Description

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted link to a Goobi viewer installation, resulting in the execution of malicious script code in the user's browser. The vulnerability has been fixed in version 23.03.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 6, 2023
Updated Feb 10, 2025
Reserved Mar 29, 2023
CISA Vulnrichment
Updated Feb 10, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-7V7G-9VX6-VCG2