VDB
Sign up
MEDIUM5.4

GHSA-4399-46r4-5rmv

GeniXCMS Cross-site Scripting (XSS)

Quick fix

GHSA-4399-46r4-5rmv — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.1.1

Details

GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.1.1
Fixcomposer require genix/cms:^1.1.1

References