MEDIUM5.4
GHSA-6vfw-74wr-3chh
Cross-site Scripting in Crater Invoice
Quick fix
GHSA-6vfw-74wr-3chh — bytefury/crater: upgrade to the fixed version with the command below.
composer require bytefury/crater:^6.0.0Details
Crater invoice prior to version 6.0.0 has a cross-site scripting vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0372[ADVISORY]
- https://github.com/crater-invoice/crater/pull/681[WEB]
- https://github.com/crater-invoice/crater/commit/cdc913d16cf624aee852bc9163a7c6ffc8d1da9d[WEB]
- https://github.com/crater-invoice/crater[PACKAGE]
- https://huntr.dev/bounties/563232b9-5a93-4f4d-8389-ed805b262ef1[WEB]