PT-2026-69841 · Magnolia · Magnolia Cms
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Magnolia CMS versions prior to 6.3.10
Description
Stored Cross-Site Scripting (XSS) exists in the import functionality. An attacker with editor privileges can inject arbitrary HTML and JavaScript into the name of an uploaded image, which is then rendered and executed when the image is opened.
Recommendations
Update to version 6.3.10.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magnolia Cms