VDB
Sign up
MEDIUM5.4

GHSA-xrf8-cmrg-7436

Cross-site scripting (XSS) vulnerability in Grav

Details

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/getgrav/grav
Introduced in: 0

No fixed version published yet for getgrav/grav (composer). Pin to a known-safe version or switch to an alternative.

References