VDB
Sign up
MEDIUM6.1

GHSA-99rh-vxmc-7wgf

ezplatform-admin-ui Cross-site Scripting (XSS) vulnerability

Quick fix

GHSA-99rh-vxmc-7wgf — ezsystems/ezplatform-admin-ui: upgrade to the fixed version with the command below.

composer require ezsystems/ezplatform-admin-ui:^1.3.5

Details

An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezplatform-page-builder 1.1.x before 1.1.5 and 1.2.x before 1.2.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ezsystems/ezplatform-admin-ui
Introduced in: 1.3Fixed in: 1.3.5
Fixcomposer require ezsystems/ezplatform-admin-ui:^1.3.5
Packagist/ezsystems/ezplatform-admin-ui
Introduced in: 1.4Fixed in: 1.4.4
Fixcomposer require ezsystems/ezplatform-admin-ui:^1.4.4

References