Headline
GHSA-pp74-g2q5-j4jf: Stored XSS in custom meta tags
A malicious content author could create a custom meta tag and execute an arbitrary JavaScript payload. This would require convincing a legitimate user to access a page and enter a custom keyboard shortcut. This requires CMS access to exploit.
Stored XSS in custom meta tags
Moderate severity GitHub Reviewed Published Nov 21, 2022 • Updated Nov 21, 2022
Related news
CVE-2022-37421: CVE-2022-37421 Stored XSS in custom meta tags
Silverstripe silverstripe/cms through 4.11.0 allows XSS.