QID 996465
Date Published: 2024-01-04
QID 996465: PHP (Composer) Security Update for automad/automad (GHSA-7j9h-ch38-474r)
automad up to 1.10.9 is vulnerable to stored cross-site scripting in the sitename argument because the SharedController class that handles form data and saving shared information does not properly sanitize the user input on the client side when rendering the data. The attack may be launched remotely and an exploit has been disclosed publicly.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7j9h-ch38-474r for updates and patch information.
Vendor References
- GHSA-7j9h-ch38-474r -
github.com/advisories/GHSA-7j9h-ch38-474r
CVEs related to QID 996465
Software Advisories
| Advisory ID | Software | Component | Link |
|---|