{"id":"CVE-2024-56517","summary":"LGSL has a reflected XSS at /lgsl_files/lgsl_list.php","details":"LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability in the `Referer` HTTP header. The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response. Commit 7ecb839df9358d21f64cdbff5b2536af25a77de1 contains a patch for the issue.","aliases":["GHSA-ggwq-xc72-33r3"],"modified":"2026-08-12T03:51:14.837165077Z","published":"2024-12-30T16:36:08.785Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56517.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56517.json"},{"type":"ADVISORY","url":"https://github.com/tltneon/lgsl/security/advisories/GHSA-ggwq-xc72-33r3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56517"},{"type":"FIX","url":"https://github.com/tltneon/lgsl/commit/7ecb839df9358d21f64cdbff5b2536af25a77de1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tltneon/lgsl","events":[{"introduced":"0"},{"fixed":"7ecb839df9358d21f64cdbff5b2536af25a77de1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.2.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v6.2.1","v6.2.0","v6.1.1","v6.1.0","v6.0.1","v6.0.0","v5.10.3","v5.10.2","v5.10.1","v5.10.0","v5.9.6","v5.9.4","v5.9.3","v5.9.2","v5.8_php7","v5.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56517.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}