Lucene search

K
osvGoogleOSV:GHSA-69WW-WV3J-MHG4
HistoryMay 24, 2022 - 5:19 p.m.

Comments plugin stored Cross-site Scripting (XSS) via an asset volume name

2022-05-2417:19:26
Google
osv.dev
9
craft cms
comments plugin
stored xss

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for OSV:GHSA-69WW-WV3J-MHG4