globaleaks/globaleaks-whistleblowing-software

globaleaks/globaleaks-whistleblowing-software

Releases450
Frequency1 week 2 days
Last Release
Stars1.49K
GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue.