VDB
Sign up
MEDIUM5.4

GHSA-q9g7-pff4-548r

Gleez Cms Cross-site Scripting in Profile Page

Details

Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in injection of arbitrary web script or HTML via the profile page editor. The victim must navigate to the attacker's profile page to exploit this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/gleez/cms
Introduced in: 0

No fixed version published yet for gleez/cms (composer). Pin to a known-safe version or switch to an alternative.

References