Skip to content

Reflected XSS on AdminFeatures page

Moderate
PierreRambaud published GHSA-87jh-7xpg-6v93 Apr 20, 2020

Package

No package listed

Affected versions

> 1.7.6.1

Patched versions

1.7.6.5

Description

Impact

Reflected XSS on AdminFeatures page by using the id_feature parameter.

Patches

The problem is fixed in 1.7.6.5

References

Reflected XSS on OWASP
Introduced by this pull request #14721

Severity

Moderate

CVE ID

CVE-2020-5269

Weaknesses

No CWEs