VDB
Sign up
MEDIUM5.5

GHSA-q76r-7p4q-mqpw

Cockpit CMS Cross-Site Scripting vulnerability

Details

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit

No fixed version published yet for cockpit-hq/cockpit (composer). Pin to a known-safe version or switch to an alternative.

References