GHSA-7j9h-ch38-474r

    Dashboard / Vulnerabilities / GHSA-7j9h-ch38-474r

    GHSA-7j9h-ch38-474r

    Published: 21 Dec 2023Last Modified: 10 Sept 2026
    Aliases:

    Summary: Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad

    Details: ## Withdrawn Advisory This advisory has been withdrawn because only the main admin with the highest level of privilege can provide input, and there are no users other than the admin from whom data could be stolen. This link is maintained to preserve external references. ## Original Description automad up to 1.10.9 is vulnerable to stored cross-site scripting in the `sitename` argument because the `SharedController` class that handles form data and saving shared information does not properly sanitize the user input on the client side when rendering the data. The attack may be launched remotely and an exploit has been disclosed publicly.

    Affected packages

    Package

    Name: automad/automad

    Purl: pkg:composer/automad/automad

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.10.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7j9h-ch38-474r | CVE-DB