Description
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
Remediation
References
https://github.com/gchq/CyberChef/commit/01f0625d6a177f9c5df9281f12a27c814c2d8bcf
https://github.com/gchq/CyberChef/compare/v8.31.1...v8.31.2
https://github.com/gchq/CyberChef/issues/539
https://github.com/gchq/CyberChef/issues/544
Related Vulnerabilities
CVE-2021-33041 Vulnerability in npm package vmd
CVE-2022-29647 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-simple-mfa
CVE-2023-26487 Vulnerability in maven package org.webjars.bowergithub.vega:vega
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests