VDB
Sign up
MEDIUM5.4

GHSA-8h24-3cjr-xxmh

Evolution CMS Stored Cross-site Scripting (XSS)

Quick fix

GHSA-8h24-3cjr-xxmh — evolutioncms/evolution: upgrade to the fixed version with the command below.

composer require evolutioncms/evolution:^1.4.6

Details

Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the page weblink title parameter to the manager/ URI.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/evolutioncms/evolution
Introduced in: 1.4Fixed in: 1.4.6
Fixcomposer require evolutioncms/evolution:^1.4.6

References