adapt-security / adapt-authoring

A server-based user interface for authoring eLearning courses using the Adapt framework.
http://adaptlearning.org
10 stars 5 forks source link

Need to sanitise URL before fetch #546

Closed taylortom closed 1 year ago

taylortom commented 1 year ago

REPORTED BY SNYK

https://github.com/adapt-security/adapt-authoring-middleware/blob/master/lib/MiddlewareModule.js#L130

See: https://owasp.org/www-community/attacks/Server_Side_Request_Forgery

taylortom commented 1 year ago

Moved to https://github.com/adapt-security/adapt-authoring/issues/584