Lucene search

K
osvGoogleOSV:GHSA-P7RM-GH9G-5FR8
HistoryMay 24, 2022 - 5:18 p.m.

Image Resizer Cross-site Scripting (XSS) in the Bulk Resize action

2022-05-2417:18:39
Google
osv.dev
4
image resizer
xss
craft cms
stored xss
bulk resize

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for OSV:GHSA-P7RM-GH9G-5FR8