Server side cross-site scripting In sulu/sulu
Description
XSS Injection in Media Collection Title was possible
Impact
A logged in admin user was possible to add a script injection (XSS) in the collection title which was executed.
Workarounds
Manual patching the js files.
For more information
If you have any questions or comments about this advisory:'
Email us at security@sulu.io
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.6.41 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.