VDB
Sign up
MEDIUM4.9

GHSA-rh9f-gr6q-mpc4

moonshine Stored Cross-Site Scripting Vulnerability in Create Admin

Quick fix

GHSA-rh9f-gr6q-mpc4 — moonshine/moonshine: upgrade to the fixed version with the command below.

composer require moonshine/moonshine:^3.12.14

Details

A stored cross-site scripting (XSS) vulnerability in the Create Admin function of MoonShine v3.12.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moonshine/moonshine
Introduced in: 0Fixed in: 3.12.14
Fixcomposer require moonshine/moonshine:^3.12.14

References