VDB
Sign up
MEDIUM5.4

GHSA-5rcc-6cmj-7728

Cross-site Scripting in BookStack

Quick fix

GHSA-5rcc-6cmj-7728 — ssddanbrown/bookstack: upgrade to the fixed version with the command below.

composer require ssddanbrown/bookstack:^22.02.3

Details

Iframe tags don't have a sandbox attribute, this makes an attacker able to execute malicious javascript via an iframe and perform phishing attacks. The sandbox attribute will block script execution and prevents the content to navigate its top-level browsing context which will stop this type of attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ssddanbrown/bookstack
Introduced in: 0Fixed in: 22.02.3
Fixcomposer require ssddanbrown/bookstack:^22.02.3

References