VDB
Sign up
MEDIUM6.1

GHSA-m98q-p5gq-q5ff

eZ Publish Cross-site Scripting (XSS) vulnerability

Quick fix

GHSA-m98q-p5gq-q5ff — ezsystems/ezpublish-legacy: upgrade to the fixed version with the command below.

composer require ezsystems/ezpublish-legacy:^5.4.10

Details

eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12.0 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ezsystems/ezpublish-legacy
Introduced in: 5.4.0Fixed in: 5.4.10
Fixcomposer require ezsystems/ezpublish-legacy:^5.4.10
Packagist/ezsystems/ezpublish-legacy
Introduced in: 5.3.0Fixed in: 5.3.12.1
Fixcomposer require ezsystems/ezpublish-legacy:^5.3.12.1

References