VDB
Sign up
MEDIUM5.4

GHSA-gp82-xr77-88f4

radiant vulnerable to Cross-site Scripting

Details

There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/radiant

No fixed version published yet for radiant (bundler). Pin to a known-safe version or switch to an alternative.

References