Merge pull request #7176 from Co5mos/CVE-2022-0678

Updated CVE-2022-0678 Template
patch-1
Dhiyaneshwaran 2023-05-05 22:52:23 +05:30 committed by GitHub
commit c585da0abe
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -1,8 +1,8 @@
id: CVE-2022-0678
info:
name: Packagist <1.2.11 - Cross-Site Scripting
author: tess
name: Microweber <1.2.11 - Cross-Site Scripting
author: tess,co5mos
severity: medium
description: |
Packagist prior to 1.2.11 contains a cross-site scripting vulnerability via microweber/microweber. User can escape the meta tag because the user doesn't escape the double-quote in the $redirectUrl parameter when logging out.