Description
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
Remediation
References
https://github.com/gchq/CyberChef/issues/544
https://github.com/gchq/CyberChef/commit/01f0625d6a177f9c5df9281f12a27c814c2d8bcf
https://github.com/gchq/CyberChef/compare/v8.31.1...v8.31.2
https://github.com/gchq/CyberChef/issues/539
Related Vulnerabilities
CVE-2017-5653 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-xml
CVE-2022-1440 Vulnerability in npm package git-interface
CVE-2019-10158 Vulnerability in maven package org.infinispan:infinispan-spring5-common
CVE-2022-24999 Vulnerability in maven package org.webjars:qs
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk18on