VDB
Sign up
MEDIUM6.8

GHSA-qxpq-82f3-xj47

CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS

Quick fix

GHSA-qxpq-82f3-xj47 — ci4-cms-erp/ci4ms: upgrade to the fixed version with the command below.

composer require ci4-cms-erp/ci4ms:^0.31.5.0

Details

An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ci4-cms-erp/ci4ms
Introduced in: 0Fixed in: 0.31.5.0
Fixcomposer require ci4-cms-erp/ci4ms:^0.31.5.0

References