VDB
Sign up
MEDIUM6.1

GHSA-9v3w-m552-m6ff

Pi Cross-site Scripting vulnerability

Quick fix

GHSA-9v3w-m552-m6ff — pi/pi: upgrade to the fixed version with the command below.

composer require pi/pi:^2.6.0-alpha1

Details

A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the `pi-develop/www/script/editor/markitup/preview/markdown.php` URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/pi/pi
Introduced in: 0Fixed in: 2.6.0-alpha1
Fixcomposer require pi/pi:^2.6.0-alpha1

References