Headline
GHSA-qw4w-vq8v-2wcv: Stored XSS using uppercase characters in HTMLEditor
A malicious content author could add a Javascript payload to the href attribute of a link. A similar issue was identified and fixed via CVE-2022-28803. However, the fix didn’t account for the casing of the href attribute. An attacker must have access to the CMS to exploit this issue.
Stored XSS using uppercase characters in HTMLEditor
Moderate severity GitHub Reviewed Published Nov 21, 2022