VDB
Sign up
MEDIUM6.1

GHSA-c2vx-rx6x-m9wj

FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function

Details

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/feehi/feehicms

No fixed version published yet for feehi/feehicms (composer). Pin to a known-safe version or switch to an alternative.

References