VDB
Sign up
CRITICAL9.1

GHSA-3hwx-c6cp-q972

Publify vulnerable to cross site scripting

Quick fix

GHSA-3hwx-c6cp-q972 — publify_core: upgrade to the fixed version with the command below.

bundle update publify_core

Details

Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/publify_core
Introduced in: 0Fixed in: 9.2.9
Fixbundle update publify_core

References