MEDIUM6.1
GHSA-c2vx-rx6x-m9wj
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function
Details
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/feehi/feehicms
No fixed version published yet for feehi/feehicms (composer). Pin to a known-safe version or switch to an alternative.