logo

Database

Server side cross-site scripting In sulu/sulu

Description

XSS Injection in Media Collection Title was possible

Impact

A logged in admin user was possible to add a script injection (XSS) in the collection title which was executed.

Workarounds

Manual patching the js files.

For more information

If you have any questions or comments about this advisory:'

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions