VDB
Sign up
LOW3.5

GHSA-j4rj-fgcq-wmqp

Cockpit - Content Platform vulnerable to XSS through name or email argument names

Quick fix

GHSA-j4rj-fgcq-wmqp — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.11.4

Details

A vulnerability was found in Cockpit versions up to 2.11.3. This issue affects some unknown processing instances of the file /system/users/save. The manipulation of the arguments "name" or "email" leads to cross-site scripting. The attack may be initiated remotely. Upgrading to version 2.11.4 will address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure and acted accordingly. A patch and new release were made available very quickly.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.11.4
Fixcomposer require cockpit-hq/cockpit:^2.11.4

References