GHSA-7j9h-ch38-474r

Suggest an improvement
Source
https://github.com/advisories/GHSA-7j9h-ch38-474r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7j9h-ch38-474r
Aliases
Withdrawn
2024-08-26T18:23:27Z
Published
2023-12-21T15:30:33Z
Modified
2026-09-10T03:49:59Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad
Details

Withdrawn Advisory

This advisory has been withdrawn because only the main admin with the highest level of privilege can provide input, and there are no users other than the admin from whom data could be stolen. This link is maintained to preserve external references.

Original Description

automad up to 1.10.9 is vulnerable to stored cross-site scripting in the sitename argument because the SharedController class that handles form data and saving shared information does not properly sanitize the user input on the client side when rendering the data. The attack may be launched remotely and an exploit has been disclosed publicly.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-12-29T19:28:58Z",
    "nvd_published_at": "2023-12-21T15:15:13Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / automad/automad

Package

Name
automad/automad
Purl
pkg:composer/automad/automad

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.10.9

Affected versions

1.*
1.10.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json"