VDB
Sign up
MEDIUM5.4

GHSA-3657-q433-mmpx

Canvs Canvas Cross-site Scripting (XSS) via title and content fields

Details

cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/austintoddj/canvas

No fixed version published yet for austintoddj/canvas (composer). Pin to a known-safe version or switch to an alternative.

References