Publish GHSA-96mh-7xpr-qcgw

This commit is contained in:
advisory-database[bot]
2023-10-03 21:24:54 +00:00
parent 6a3ef117b1
commit 6d0b52112b
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96mh-7xpr-qcgw",
"modified": "2023-07-21T20:43:17Z",
"modified": "2023-10-03T21:23:19Z",
"published": "2022-05-13T01:24:44Z",
"aliases": [
"CVE-2018-7198"
],
"summary": "October CMS XSS",
"details": "October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.",
"summary": "October CMS - RainLab Blog Plugin XSS",
"details": "The RainLab Blog Plugin used in October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.",
"severity": [
{
"type": "CVSS_V3",
@@ -18,7 +18,12 @@
{
"package": {
"ecosystem": "Packagist",
"name": "october/october"
"name": "rainlab/blog-plugin"
},
"ecosystem_specific": {
"affected_functions": [
""
]
},
"ranges": [
{
@@ -28,7 +33,7 @@
"introduced": "0"
},
{
"last_affected": "1.0.431"
"fixed": "1.4.1"
}
]
}
@@ -40,9 +45,13 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-7198"
},
{
"type": "WEB",
"url": "https://github.com/rainlab/blog-plugin/commit/6ae19a6e16ef3ba730692bc899851342c858bb94"
},
{
"type": "PACKAGE",
"url": "https://github.com/octobercms/october/"
"url": "https://github.com/rainlab/blog-plugin"
},
{
"type": "WEB",