Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wc6r-4ggc-79w5: Stored XSS using HTMLEditor

A malicious content author could add a JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.

An attacker must have access to the CMS to exploit this issue.

ghsa
#xss#git#java#auth

Stored XSS using HTMLEditor

Moderate severity GitHub Reviewed Published Nov 21, 2022 • Updated Nov 21, 2022

ghsa: Latest News

GHSA-mqf3-qpc3-g26q: Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message