ansibleguy-webui Cross-site Scripting vulnerability
        
  High severity
        
          GitHub Reviewed
      
        Published
          May 28, 2024 
          in
          
            O-X-L/ansible-webui-v0
          
          •
          Updated Jun 3, 2024 
      
  
Description
        Published by the National Vulnerability Database
      May 28, 2024 
    
  
        Published to the GitHub Advisory Database
      May 28, 2024 
    
  
        Reviewed
      May 28, 2024 
    
  
        Last updated
      Jun 3, 2024 
    
  
Impact
Multiple forms in version <0.0.21 allowed injection of HTML elements.
These are returned to the user after executing job actions and thus evaluated by the browser.
Patches
We recommend to upgrade to version >= 0.0.21
References
References