Skip to content

Cross-site Scripting (XSS) in perspective name

Moderate
dvesh3 published GHSA-fq8q-55v3-2986 Apr 3, 2023

Package

composer pimcore/perspective-editor (Composer)

Affected versions

< 1.5.1

Patched versions

1.5.1

Description

Impact

This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites.

Patches

Update to version 1.5.1 or apply this patch manually https://github.com/pimcore/perspective-editor/pull/121.patch

Workarounds

Apply patch https://github.com/pimcore/perspective-editor/pull/121.patch manually.

References

https://huntr.dev/bounties/5529f51e-e40f-46f1-887b-c9dbebab4f06/

Severity

Moderate

CVE ID

CVE-2023-28850

Weaknesses

Credits