Описание
Publify vulnerable to cross site scripting
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained.
Пакеты
Наименование
publify_core
rubygems
Затронутые версииВерсия исправления
< 9.2.9
9.2.9
Связанные уязвимости
CVSS3: 5.4
nvd
больше 3 лет назад
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.