CVE-2024-47067
MEDIUMAList < 3.29.0 - Reflected Cross-Site Scripting via /i/:link_name Endpoint
Title source: llmDescription
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://securitylab.github.com/advisories/GHSL-2023-220_Alist/
Scores
CVSS v3
6.1
EPSS
0.0039
EPSS Percentile
30.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
alist-org/alist
0 - 3.29.0Go
alistgo/alist
< 3.29.0
Published
Sep 30, 2024
Tracked Since
Feb 18, 2026