Headline
GHSA-66jf-xm2m-7m8r: Stored XSS in Compare Mode
A malicious content author could add a Javascript payload to a page’s meta description and get it executed in the versioned history compare view.
This vulnerability requires access to the CMS to be deployed. The attacker must then convince a privileged user to access the version history for that page.
Stored XSS in Compare Mode
Moderate severity GitHub Reviewed Published Nov 22, 2022 • Updated Nov 22, 2022