VDB
Sign up
MEDIUM5.4

GHSA-9mfc-gr8c-xj4m

Evolution CMS Cross-site Scripting (XSS)

Quick fix

GHSA-9mfc-gr8c-xj4m — evolutioncms/evolution: upgrade to the fixed version with the command below.

composer require evolutioncms/evolution:^1.4.6

Details

Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the manager/ search parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/evolutioncms/evolution
Introduced in: 1.4.0Fixed in: 1.4.6
Fixcomposer require evolutioncms/evolution:^1.4.6

References