VDB
Sign up
MEDIUM5.4

GHSA-j2fp-9wp5-mg66

Passbolt API is vulnerable to XSS in the url field on the password workspace grid and sidebar

Quick fix

GHSA-j2fp-9wp5-mg66 — passbolt/passbolt_api: upgrade to the fixed version with the command below.

composer require passbolt/passbolt_api:^1.6.5

Details

Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/passbolt/passbolt_api
Introduced in: 0Fixed in: 1.6.5
Fixcomposer require passbolt/passbolt_api:^1.6.5

References