VDB
Sign up
CRITICAL9.1

GHSA-5ghq-42rg-769x

CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS

Quick fix

GHSA-5ghq-42rg-769x — ci4-cms-erp/ci4ms: upgrade to the fixed version with the command below.

composer require ci4-cms-erp/ci4ms:^0.31.2.0

Details

An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ci4-cms-erp/ci4ms
Introduced in: 0Fixed in: 0.31.2.0
Fixcomposer require ci4-cms-erp/ci4ms:^0.31.2.0

References