The name of the releases are not properly escaped on the edition page of a release
Impact
A malicious user with the ability to create a FRS release could force a victim having write permissions in the FRS to execute uncontrolled code.
CVSSv3.1 score: 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Exploitation
- Create a release named
"></select><img src=a onerror=alert(1)>
- Edit another release
References
CWE 79
OWASP Cross-site Scripting
CVE-2023-48715
Acknowledgements
This issue was identified thanks to Psalm taint analysis.