MEDIUM6.1
GHSA-6fh7-fwqj-mv49
HTML Purifier Cross-site Scripting vulnerability
Quick fix
GHSA-6fh7-fwqj-mv49 — ezyang/htmlpurifier: upgrade to the fixed version with the command below.
composer require ezyang/htmlpurifier:^2.0.1Details
Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "unescaped print_r output."
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezyang/htmlpurifier
Introduced in:
0Fixed in: 2.0.1Fix
composer require ezyang/htmlpurifier:^2.0.1References
- https://nvd.nist.gov/vuln/detail/CVE-2007-3498[ADVISORY]
- https://github.com/ezyang/htmlpurifier/commit/96b571d23639bd70768b8db626ecaf8bbb7ca5a3[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35300[WEB]
- https://github.com/ezyang/htmlpurifier[PACKAGE]
- https://github.com/ezyang/htmlpurifier/commits/v2.0.1/smoketests/configForm.php[WEB]
- https://web.archive.org/web/20200228110020/http://www.securityfocus.com/bid/24699[WEB]
- http://htmlpurifier.org/svnroot/htmlpurifier/tags/2.0.1/NEWS[WEB]