Lucene search

K
osvGoogleOSV:GHSA-WMH9-X28J-C6GR
HistoryMay 24, 2022 - 10:29 p.m.

Cross site scripting in publify

2022-05-2422:29:03
Google
osv.dev
8
publify
cross site scripting
stored xss
arbitrary javascript code
publisher role
security vulnerability

EPSS

0.001

Percentile

19.4%

In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.

EPSS

0.001

Percentile

19.4%

Related for OSV:GHSA-WMH9-X28J-C6GR