QID 996674
Date Published: 2024-01-15
QID 996674: PHP (Composer) Security Update for elefant/cms (GHSA-qjjq-rcq8-jw6j)
Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x before 1.1.5-Beta allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body parameter to admin/preview.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qjjq-rcq8-jw6j for updates and patch information.
Vendor References
- GHSA-qjjq-rcq8-jw6j -
github.com/advisories/GHSA-qjjq-rcq8-jw6j
CVEs related to QID 996674
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qjjq-rcq8-jw6j | elefant/cms |
|