Skip to content

Inline attribute values were not processed.

High
tabuna published GHSA-589w-hccm-265x Oct 19, 2020

Package

composer orchid/platform (Composer)

Affected versions

9.0.0<9.4.3

Patched versions

9.4.4

Description

Impact

Inline attributes have not been processed escape.
If the data that came from users was not processed, then an XSS vulnerability is possible

Patches

Fixed in 9.4.4

Severity

High

CVE ID

CVE-2020-15263

Weaknesses

No CWEs