Lucene search

K
osvGoogleOSV:GHSA-JHHF-C849-3RH2
HistoryMay 24, 2022 - 5:19 p.m.

Comments plugin stored Cross-site Scripting via a guest name

2022-05-2417:19:26
Google
osv.dev
3
comments plugin
craft cms
stored xss

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via a guest name.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for OSV:GHSA-JHHF-C849-3RH2