VDB
Sign up
LOW3.5

GHSA-w4pj-7p68-3vgv

Stored XSS in October

Quick fix

GHSA-w4pj-7p68-3vgv — october/backend: upgrade to the fixed version with the command below.

composer require october/backend:^1.0.466

Details

### Impact A user with access to a markdown FormWidget that stores data persistently could create a stored XSS attack against themselves and any other users with access to the generated HTML from the field.

### Patches Issue has been patched in Build 466 (v1.0.466) & RainLab.Blog v1.4.1 by restricting the ability to store JS in markdown to only users that have been explicitly granted the `backend.allow_unsafe_markdown` permission.

### Workarounds Apply https://github.com/octobercms/october/commit/9ecfb4867baae14a0d3f99f5b5c1e8a979ae8746 & https://github.com/rainlab/blog-plugin/commit/6ae19a6e16ef3ba730692bc899851342c858bb94 to your installation manually if unable to upgrade to Build 466 or v1.4.1 of RainLab.Blog (if using that plugin).

### References Reported by [Sivanesh Ashok](https://stazot.com/)

### For more information If you have any questions or comments about this advisory: * Email us at [hello@octobercms.com](mailto:hello@octobercms.com)

### Threat assessment: <img width="1100" alt="Screen Shot 2020-03-31 at 2 01 52 PM" src="https://user-images.githubusercontent.com/7253840/78070158-8f7ef580-7358-11ea-950c-226533f6a0a3.png">

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/october/backend
Introduced in: 1.0.319Fixed in: 1.0.466
Fixcomposer require october/backend:^1.0.466

References