Skip to content

Stored XSS on back office edit page

Low
PierreRambaud published GHSA-vr7g-vqp5-966j Apr 15, 2020

Package

No package listed

Affected versions

> 1.0.4

Patched versions

3.1.0

Description

Impact

Stored XSS when you create or edit a link list block with the title field.

Patches

The problem is fixed in 3.1.0

References

Cross-site Scripting (XSS) - Stored (CWE-79)

Severity

Low

CVE ID

CVE-2020-5266

Weaknesses

No CWEs