MEDIUM4.8
GHSA-478j-mcrr-3877
GeniXCMS Cross-site scripting (XSS) vulnerability
Details
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/genix/cms
No fixed version published yet for genix/cms (composer). Pin to a known-safe version or switch to an alternative.