GHSA-wf98-vxv9-jqfv
Dashboard / Vulnerabilities / GHSA-wf98-vxv9-jqfv
GHSA-wf98-vxv9-jqfv
Summary: XSS Injection Vulnerability
Details: ### Impact Under some circumstances, the Feeds widget on the dashboard could have an XSS vulnerability if a malformed feed was supplied. ### Patches This has been patched in Craft 3.7.29. ### References * https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#3729---2022-01-18 ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected]) ---------- Credits: https://github.com/noobpk
References: https://github.com/craftcms/cms/security/advisories/GHSA-wf98-vxv9-jqfv, https://github.com/craftcms/cms
Affected packages
Package
Name: craftcms/cms
Purl: pkg:composer/craftcms/cms
Affected ranges
Type: ECOSYSTEM
Events:
