MEDIUM5.5
GHSA-q76r-7p4q-mqpw
Cockpit CMS Cross-Site Scripting vulnerability
Details
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cockpit-hq/cockpit
No fixed version published yet for cockpit-hq/cockpit (composer). Pin to a known-safe version or switch to an alternative.