Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qw4w-vq8v-2wcv: Stored XSS using uppercase characters in HTMLEditor

A malicious content author could add a Javascript payload to the href attribute of a link. A similar issue was identified and fixed via CVE-2022-28803. However, the fix didn’t account for the casing of the href attribute. An attacker must have access to the CMS to exploit this issue.

ghsa
#xss#git#java#auth

Stored XSS using uppercase characters in HTMLEditor

Moderate severity GitHub Reviewed Published Nov 21, 2022

ghsa: Latest News

GHSA-mqf3-qpc3-g26q: Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message