GNOME gi-docgen Reflected DOM-Based Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in GNOME gi-docgen. This issue allows for arbitrary execution of JavaScript in the context of the page, which could lead to access of the Document Object Model (DOM), theft of session cookies, and other client-side attacks. The vulnerability arises because gi-docgen does not properly encode search terms before inserting them into HTML. It can be exploited by sending a crafted URL that includes a malicious value in the 'q' GET parameter.
Impact
Exploitation of this vulnerability allows for reflected DOM-based cross-site scripting, where an attacker can execute arbitrary JavaScript in the victim's browser. This could be used to steal cookies, including session cookies, and perform other client-side attacks.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
