VDB
Sign up
MEDIUM4.8

GHSA-5hf2-7xf4-w3j6

GeniXCMS Cross-site Scripting

Quick fix

GHSA-5hf2-7xf4-w3j6 — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.1.0

Details

GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.1.0
Fixcomposer require genix/cms:^1.1.0

References