Skip to content

Stored Cross-site Scripting (XSS)

Moderate
trasher published GHSA-28fg-cp22-6c33 Dec 16, 2021

Package

Galette core (PHP)

Affected versions

< 0.9.6

Patched versions

0.9.6

Description

Impact

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user.

This therefore requires admin rigths.

Patches

Upgrade to 0.9.6. No workaround is available.

Severity

Moderate

CVE ID

CVE-2021-41261

Weaknesses

No CWEs

Credits