Withdrawn Advisory: Kirby CMS HTML injection vulnerability
High severity
GitHub Reviewed
Published
Feb 22, 2024
to the GitHub Advisory Database
•
Updated Aug 30, 2024
Withdrawn
This advisory was withdrawn on Aug 30, 2024
Description
Published by the National Vulnerability Database
Feb 22, 2024
Published to the GitHub Advisory Database
Feb 22, 2024
Reviewed
Feb 26, 2024
Last updated
Aug 30, 2024
Withdrawn
Aug 30, 2024
Withdrawn Advisory
This advisory has been withdrawn because the vendor reports that some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious scripts" would not occur.
Original Advisory
An HTML injection vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted payload.
References