MEDIUM
GHSA-38m8-5gfc-663g
Enhavo Cross-site Scripting vulnerability
Details
A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Create Tag text field.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/enhavo/enhavo-app
Introduced in:
0No fixed version published yet for enhavo/enhavo-app (composer). Pin to a known-safe version or switch to an alternative.