MEDIUM5.4
GHSA-4399-46r4-5rmv
GeniXCMS Cross-site Scripting (XSS)
Quick fix
GHSA-4399-46r4-5rmv — genix/cms: upgrade to the fixed version with the command below.
composer require genix/cms:^1.1.1Details
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-8762[ADVISORY]
- https://github.com/semplon/GeniXCMS/issues/73[WEB]
- https://github.com/semplon/GeniXCMS/commit/5a128e830fa4a830137d03842c8e8bb22107cadf[WEB]
- https://github.com/semplon/GeniXCMS/commit/e75e7447455da89a0cab965ba46f91f38cfd62d2[WEB]
- https://github.com/GeniXCMS/GeniXCMS[PACKAGE]