CRITICAL9.1
GHSA-5ghq-42rg-769x
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Quick fix
GHSA-5ghq-42rg-769x — ci4-cms-erp/ci4ms: upgrade to the fixed version with the command below.
composer require ci4-cms-erp/ci4ms:^0.31.2.0Details
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ci4-cms-erp/ci4ms
Introduced in:
0Fixed in: 0.31.2.0Fix
composer require ci4-cms-erp/ci4ms:^0.31.2.0