An issue was discovered in whatanime.ga before c334dd8499a681587dd4199e90b0aa0eba814c1d. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "whatanime.ga-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6390.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "34c7155c6fd82b7746fe8b56eb89bf278553c421"
}
]
},
{
"events": [
{
"introduced": "whatanime.ga"
},
{
"fixed": "c334dd8499a681587dd4199e90b0aa0eba814c1d"
}
]
}
]