Cross-site Scripting (XSS) Affecting geshi package, versions *


Severity

Recommended
0.0
low
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIAN12-GESHI-9376926
  • published10 Mar 2025
  • disclosed9 Mar 2025

Introduced: 9 Mar 2025

NewCVE-2025-2123  (opens in a new tab)
CWE-79  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 geshi.

NVD Description

Note: Versions mentioned in the description apply only to the upstream geshi package and not the geshi package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the file /contrib/cssgen.php of the component CSS Handler. The manipulation of the argument default-styles/keywords-1/keywords-2/keywords-3/keywords-4/comments leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS Base Scores

version 3.1