This advisory has been withdrawn because it does not describe a vulnerability. The maintainer states the following:
The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized.
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2023-08-01T20:57:57Z",
"nvd_published_at": "2018-10-16T22:29:00Z",
"severity": "MODERATE"
}