VDB
Sign up
MEDIUM5.4

GHSA-5mqq-7g25-r4wx

FeehiCMS vulnerable to Cross-Site scripting via crafted payload

Details

FeehiCMS versions 2.0.1.1 and prior contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. There are no patches and no known workarounds for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/feehi/feehicms
Introduced in: 0

No fixed version published yet for feehi/feehicms (composer). Pin to a known-safe version or switch to an alternative.

References