An issue was discovered in Nim before 1.6.2. The RST...
Moderate severity
Unreviewed
Published
Jan 13, 2023
to the GitHub Advisory Database
•
Updated Jan 23, 2023
Description
Published by the National Vulnerability Database
Jan 13, 2023
Published to the GitHub Advisory Database
Jan 13, 2023
Last updated
Jan 23, 2023
An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)
References