MEDIUM6.1
GHSA-9v3w-m552-m6ff
Pi Cross-site Scripting vulnerability
Quick fix
GHSA-9v3w-m552-m6ff — pi/pi: upgrade to the fixed version with the command below.
composer require pi/pi:^2.6.0-alpha1Details
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the `pi-develop/www/script/editor/markitup/preview/markdown.php` URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-7251[ADVISORY]
- https://github.com/pi-engine/pi/issues/1523[WEB]
- https://github.com/pi-engine/pi/commit/557cd05b21b4d7fe422f90adcfa0c6e3bea06153[WEB]
- https://github.com/pi-engine/pi[PACKAGE]
- https://web.archive.org/web/20210124010656/https://www.securityfocus.com/bid/97061[WEB]