Описание
Pagekit CMS cross-site scripting in Markdown text box where articles are edited
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.
Пакеты
Наименование
pagekit/pagekit
composer
Затронутые версииВерсия исправления
<= 1.0.18
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
больше 3 лет назад
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.