VDB
Sign up
MEDIUM5.4

GHSA-p7rm-gh9g-5fr8

Image Resizer Cross-site Scripting (XSS) in the Bulk Resize action

Quick fix

GHSA-p7rm-gh9g-5fr8 — verbb/image-resizer: upgrade to the fixed version with the command below.

composer require verbb/image-resizer:^2.0.9

Details

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/verbb/image-resizer
Introduced in: 0Fixed in: 2.0.9
Fixcomposer require verbb/image-resizer:^2.0.9

References