XSS Injection in Media Collection Title was possible
Description
Reviewed
Jul 2, 2021
Published by the National Vulnerability Database
Jul 2, 2021
Published to the GitHub Advisory Database
Jul 2, 2021
Last updated
Feb 1, 2023
Impact
A logged in admin user was possible to add a script injection (XSS) in the collection title which was executed.
Workarounds
Manual patching the js files.
For more information
If you have any questions or comments about this advisory:'
References