QID 997259
Date Published: 2024-02-20
QID 997259: PHP (Composer) Security Update for getgrav/grav (GHSA-xrf8-cmrg-7436)
A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xrf8-cmrg-7436 for updates and patch information.
Vendor References
- GHSA-xrf8-cmrg-7436 -
github.com/advisories/GHSA-xrf8-cmrg-7436
CVEs related to QID 997259
Software Advisories
| Advisory ID | Software | Component | Link |
|---|