QID 997945
Date Published: 2024-04-08
QID 997945: PHP (Composer) Security Update for elgg/elgg (GHSA-mcfm-j5g6-w26f)
The internalname parameter is not properly sanitized, which allows attacker to conduct Cross Site Scripting attack. This may allow an attacker to create a specially crafted URL that would execute arbitrary script code in a victim's browser
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mcfm-j5g6-w26f for updates and patch information.
Vendor References
- GHSA-mcfm-j5g6-w26f -
github.com/advisories/GHSA-mcfm-j5g6-w26f
CVEs related to QID 997945
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mcfm-j5g6-w26f | elgg/elgg |
|