movingbytes/social-network
works pretty similar to a well known social network, but you can host it on your very own infrastructure or intranet.
Activity
- Latest release
- 10y ago
- Total releases
- 3
- Cadence
- ~9 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Mar 15, 2016
| Version | Released | |
|---|---|---|
v1.2.1
patch
deprecated
1 CVE
CVE-2017-7390
GHSA-3fm8-7gpf-p8fm
May 17, 2022
SocialNetwork Cross-Site Scripting (XSS) vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. A patch for the vulnerability is available at https://github.com/andreas83/SocialNetwork/commit/1b0799d08fda2f3099beaae1234b8b468deb8db1 Affected versions
v1.0
v1.1
v1.2
v1.2.1
References Updated Apr 24, 2024 · Source: OSV.dev | ||
v1.2
minor
1 CVE
CVE-2017-7390
GHSA-3fm8-7gpf-p8fm
May 17, 2022
SocialNetwork Cross-Site Scripting (XSS) vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. A patch for the vulnerability is available at https://github.com/andreas83/SocialNetwork/commit/1b0799d08fda2f3099beaae1234b8b468deb8db1 Affected versions
v1.0
v1.1
v1.2
v1.2.1
References Updated Apr 24, 2024 · Source: OSV.dev | ||
v1.1
initial
1 CVE
CVE-2017-7390
GHSA-3fm8-7gpf-p8fm
May 17, 2022
SocialNetwork Cross-Site Scripting (XSS) vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. A patch for the vulnerability is available at https://github.com/andreas83/SocialNetwork/commit/1b0799d08fda2f3099beaae1234b8b468deb8db1 Affected versions
v1.0
v1.1
v1.2
v1.2.1
References Updated Apr 24, 2024 · Source: OSV.dev |