Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qw4w-vq8v-2wcv: Stored XSS using uppercase characters in HTMLEditor

A malicious content author could add a Javascript payload to the href attribute of a link. A similar issue was identified and fixed via CVE-2022-28803. However, the fix didn’t account for the casing of the href attribute. An attacker must have access to the CMS to exploit this issue.

ghsa
#xss#git#java#auth

Stored XSS using uppercase characters in HTMLEditor

Moderate severity GitHub Reviewed Published Nov 21, 2022

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails