Description
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`. Version 0.70.0 fixes the issue.
Problem types
CWE-20: Improper Input Validation
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
References
github.com/...movary/security/advisories/GHSA-pj3m-gmq8-2r57
github.com/...ob/main/public/js/settings-account-location.js
github.com/leepeuker/movary/releases/tag/0.70.0