MEDIUM5.4
GHSA-9mfc-gr8c-xj4m
Evolution CMS Cross-site Scripting (XSS)
Quick fix
GHSA-9mfc-gr8c-xj4m — evolutioncms/evolution: upgrade to the fixed version with the command below.
composer require evolutioncms/evolution:^1.4.6Details
Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the manager/ search parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/evolutioncms/evolution
Introduced in:
1.4.0Fixed in: 1.4.6Fix
composer require evolutioncms/evolution:^1.4.6References
- https://nvd.nist.gov/vuln/detail/CVE-2018-16638[ADVISORY]
- https://github.com/evolution-cms/evolution/issues/789[WEB]
- https://github.com/evolution-cms/evolution/commit/b59d1f57be37ab752d65be4bc4d3546c36b69415[WEB]
- https://github.com/evolution-cms/evolution[PACKAGE]
- https://github.com/security-breachlock/CVE-2018-16638/blob/master/evolution_xss_reflected.pdf[WEB]