AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Oct 16, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Aug 1, 2023
Last updated
Mar 21, 2024
A stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image filename field.
References