MEDIUM5.4
GHSA-3657-q433-mmpx
Canvs Canvas Cross-site Scripting (XSS) via title and content fields
Details
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/austintoddj/canvas
No fixed version published yet for austintoddj/canvas (composer). Pin to a known-safe version or switch to an alternative.