VDB
Sign up
MEDIUM5.4

GHSA-5ffj-mph5-c5hv

Appwrite Vulnerable to Cross-site Scripting

Quick fix

GHSA-5ffj-mph5-c5hv — appwrite/server-ce: upgrade to the fixed version with the command below.

composer require appwrite/server-ce:^1.0.0-RC1

Details

Appwrite is vulnerable to stored cross-site scripting in usernames, function names, storage bucket names, and database collection names.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/appwrite/server-ce
Introduced in: 0Fixed in: 1.0.0-RC1
Fixcomposer require appwrite/server-ce:^1.0.0-RC1

References