Lucene search

K
osvGoogleOSV:GHSA-GM2X-6475-G9R8
HistoryJul 02, 2021 - 6:32 p.m.

XSS Injection in Media Collection Title was possible

2021-07-0218:32:18
Google
osv.dev
12
xss
injection
media
collection
title
js
patching
security

EPSS

0.001

Percentile

19.4%

Impact

A logged in admin user was possible to add a script injection (XSS) in the collection title which was executed.

Workarounds

Manual patching the js files.

For more information

If you have any questions or comments about this advisory:’

EPSS

0.001

Percentile

19.4%

Related for OSV:GHSA-GM2X-6475-G9R8