MEDIUM5.4
GHSA-8h24-3cjr-xxmh
Evolution CMS Stored Cross-site Scripting (XSS)
Quick fix
GHSA-8h24-3cjr-xxmh — evolutioncms/evolution: upgrade to the fixed version with the command below.
composer require evolutioncms/evolution:^1.4.6Details
Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the page weblink title parameter to the manager/ URI.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/evolutioncms/evolution
Introduced in:
1.4Fixed in: 1.4.6Fix
composer require evolutioncms/evolution:^1.4.6References
- https://nvd.nist.gov/vuln/detail/CVE-2018-16637[ADVISORY]
- https://github.com/evolution-cms/evolution/issues/788[WEB]
- https://github.com/evolution-cms/evolution/commit/2b8aaa6224997155de0fe9440ad106bd98dc4f4b[WEB]
- https://github.com/evolution-cms/evolution[PACKAGE]
- https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf[WEB]