CVE-2025-53903: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in The-Scratch-Channel the-scratch-channel.github.io
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac29001abb1a3cac0964b8ddb addresses this issue.
CVE-2025-53903: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in The-Scratch-Channel the-scratch-channel.github.io
Description
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac29001abb1a3cac0964b8ddb addresses this issue.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-07-11T19:05:23.826Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68769e9ca83201eaaccfda5e
Added to database: 7/15/2025, 6:31:56 PM
Last updated: 7/15/2025, 6:31:56 PM
Views: 1
Related Threats
CVE-2025-7657: Use after free in Google Chrome
HighCVE-2025-7656: Integer overflow in Google Chrome
HighCVE-2025-6558: Insufficient validation of untrusted input in Google Chrome
HighCVE-2025-26186: n/a
HighCVE-2025-53959: CWE-862 in JetBrains YouTrack
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.