MEDIUM4.5
GHSA-p632-58pp-c9xg
moonshine Stored Cross-Site Scripting Vulnerability in Create Article
Quick fix
GHSA-p632-58pp-c9xg — moonshine/moonshine: upgrade to the fixed version with the command below.
composer require moonshine/moonshine:^3.12.4Details
A stored cross-site scripting (XSS) vulnerability in the Create Article function of MoonShine v3.12.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Link parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/moonshine/moonshine
Introduced in:
0Fixed in: 3.12.4Fix
composer require moonshine/moonshine:^3.12.4