Description
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-692: Incomplete Denylist to Cross-Site Scripting
Product status
References
github.com/...hub.io/security/advisories/GHSA-hgh4-pj74-f5rr
github.com/...ratch-channel.github.io/blob/main/api/admin.js