Headline
CVE-2018-25086: Release FanPress CM 3.6.4 · sea75300/fanpresscm3
A vulnerability was found in sea75300 FanPress CM up to 3.6.3. It has been classified as problematic. This affects the function getArticlesPreview of the file inc/controller/action/system/templatepreview.php of the component Template Preview. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 3.6.4 is able to address this issue. The name of the patch is c380d343c2107fcee55ab00eb8d189ce5e03369b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230235.
Todays new release 3.6.4 of FanPress CM contains fixes for two issues.
- Using PHP 7 an issue might prevent the system help from loading correctly resulting in an empty page.
- The second fix disables <script> tags inside the template preview due to possible use for cross-site-scripting inside FanPress CM.
The development of FanPress CM 4 started recently. The new major version will come with a completely new extension system and other major changes. See https://github.com/sea75300/fanpresscm4 for further progress.