Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0145: Fix xss though the description in the info.xml file of a theme or module · forkcms/forkcms@981730f

Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE
#xss#git

@@ -839,7 +839,7 @@ public static function processModuleXml(\SimpleXMLElement $xml): array $information[‘name’] = (string) $module->name; $information[‘version’] = (string) $module->version; $information[‘requirements’] = (array) $module->requirements; $information[‘description’] = (string) $module->description; $information[‘description’] = strip_tags((string) $module->description, ‘<h1><h2><h3><h4><h5><h6><p><li><a>’); $information[‘cronjobs’] = [];
// authors @@ -900,7 +900,7 @@ public static function processThemeXml(\SimpleXMLElement $xml): array $information[‘version’] = (string) $theme->version; $information[‘requirements’] = (array) $theme->requirements; $information[‘thumbnail’] = (string) $theme->thumbnail; $information[‘description’] = (string) $theme->description; $information[‘description’] = strip_tags((string) $theme->description, ‘<h1><h2><h3><h4><h5><h6><p><li><a>’);
// authors foreach ($xml->xpath(‘/theme/authors/author’) as $author) {

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907