Headline
GHSA-fgxj-g7x3-85cq: Stored cross site scripting in RSS displayer
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
Stored cross site scripting in RSS displayer
Low severity GitHub Reviewed Published Apr 28, 2023 to the GitHub Advisory Database • Updated May 1, 2023