CRITICAL9.0
GHSA-p3w3-4ppm-c3f6
Cross site scripting in FacturaScripts
Quick fix
GHSA-p3w3-4ppm-c3f6 — facturascripts/facturascripts: upgrade to the fixed version with the command below.
composer require facturascripts/facturascripts:^2022.06Details
FacturaScripts prior to version 2022.06 is vulnerable to stored cross-site scripting via upload plugin functionality in zip format.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/facturascripts/facturascripts
Introduced in:
0Fixed in: 2022.06Fix
composer require facturascripts/facturascripts:^2022.06