commit
c585da0abe
|
@ -1,8 +1,8 @@
|
|||
id: CVE-2022-0678
|
||||
|
||||
info:
|
||||
name: Packagist <1.2.11 - Cross-Site Scripting
|
||||
author: tess
|
||||
name: Microweber <1.2.11 - Cross-Site Scripting
|
||||
author: tess,co5mos
|
||||
severity: medium
|
||||
description: |
|
||||
Packagist prior to 1.2.11 contains a cross-site scripting vulnerability via microweber/microweber. User can escape the meta tag because the user doesn't escape the double-quote in the $redirectUrl parameter when logging out.
|
||||
|
|
Loading…
Reference in New Issue