Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1xampxLXJjcTgtanc2as4AAaMb

Elefant CMS Multiple XSS Vulnerabilities

Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x before 1.1.5-Beta allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body parameter to admin/preview.

Permalink: https://github.com/advisories/GHSA-qjjq-rcq8-jw6j
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xampxLXJjcTgtanc2as4AAaMb
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 4 months ago


Identifiers: GHSA-qjjq-rcq8-jw6j, CVE-2012-1296
References: Repository: https://github.com/jbroadway/elefant
Blast Radius: 0.0

Affected Packages

packagist:elefant/cms
Dependent packages: 0
Dependent repositories: 4
Downloads: 852 total
Affected Version Ranges: >= 1.1, < 1.1.5-Beta, >= 1.0, < 1.0.2-Beta
Fixed in: 1.1.5-Beta, 1.0.2-Beta
All affected versions:
All unaffected versions: