Medium severityOSV Advisory· Published Dec 30, 2024· Updated Jun 17, 2026
CVE-2024-56517
CVE-2024-56517
Description
LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability in the Referer HTTP header. The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the Referer header, it is echoed back into an HTML attribute in the application’s response. Commit 7ecb839df9358d21f64cdbff5b2536af25a77de1 contains a patch for the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tltneon/lgslPackagist | <= 6.2.1 | — |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-ggwq-xc72-33r3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-56517ghsaADVISORY
- github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.phpnvdWEB
- github.com/tltneon/lgsl/commit/7ecb839df9358d21f64cdbff5b2536af25a77de1nvdWEB
- github.com/tltneon/lgsl/security/advisories/GHSA-ggwq-xc72-33r3nvdWEB
News mentions
0No linked articles in our index yet.