Cross site scripting in Elefant CMS
Moderate severity
GitHub Reviewed
Published
Jun 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 20, 2022
Published to the GitHub Advisory Database
Jun 21, 2022
Reviewed
Jun 29, 2022
Last updated
Jan 27, 2023
A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
References