VDB
Sign up
MEDIUM5.4

GHSA-jvjp-vh27-r9h5

Cross-site Scripting in PiranhaCMS

Quick fix

GHSA-jvjp-vh27-r9h5 — Piranha: upgrade to the fixed version with the command below.

dotnet add package Piranha --version 9.2.0

Details

In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Piranha
Introduced in: 7.0.0Fixed in: 9.2.0
Fixdotnet add package Piranha --version 9.2.0

References