MEDIUM5.4
GHSA-69ww-wv3j-mhg4
Comments plugin stored Cross-site Scripting (XSS) via an asset volume name
Quick fix
GHSA-69ww-wv3j-mhg4 — verbb/comments: upgrade to the fixed version with the command below.
composer require verbb/comments:^1.5.5Details
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
Are you affected?
Enter the version of the package you're using.