QID 996108
Date Published: 2023-11-30
QID 996108: PHP (Composer) Security Update for october/system (GHSA-rvx8-p3xp-fj3p)
A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rvx8-p3xp-fj3p for updates and patch information.
Vendor References
- GHSA-rvx8-p3xp-fj3p -
github.com/advisories/GHSA-rvx8-p3xp-fj3p
CVEs related to QID 996108
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rvx8-p3xp-fj3p | october/system |
|