Skip to content

Reflected XSS with parameters in PostComment

Moderate
PierreRambaud published GHSA-58w4-w77w-qv3w Nov 16, 2020

Package

No package listed

Affected versions

> 4.0.0

Patched versions

4.2.0

Description

Impact

An attacker could inject malicious web code into the users' web browsers by creating a malicious link.

Patches

The problem is fixed in 4.2.0

References

Cross-site Scripting (XSS) - Reflected (CWE-79)

Severity

Moderate

CVE ID

CVE-2020-26225

Weaknesses

No CWEs

Credits