GHSA-9cq2-pcgr-8h62

Suggest an improvement
Source
https://github.com/advisories/GHSA-9cq2-pcgr-8h62
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-9cq2-pcgr-8h62/GHSA-9cq2-pcgr-8h62.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9cq2-pcgr-8h62
Published
2024-05-15T21:07:54Z
Modified
2024-11-29T05:30:26.042267Z
Summary
Cross-site Scripting in eZFind spellcheck
Details

This security advisory fixes a vulnerability in the legacy eZ Find extension, which can be used with the LegacyBridge in eZ Platform. It affects sites using the "Did you mean...?" spell check / search suggestion feature. This feature is vulnerable to Cross-site Scripting (XSS) injection (reflected XSS). The update adds the necessary escaping of injected code. If you're affected, we recommend that you install it as soon as possible.

If you have custom search templates, please make sure you update these as well. Ensure that "searchextras.spellcheckcollation" is followed by the "wash" operator, like this: {$searchextras.spellcheckcollation|wash}

To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezfind/commit/51c17ea9b1231c20db8221f34d01c649060f1e91

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-15T21:07:54Z"
}
References

Affected packages

Packagist / ezsystems/ezfind-ls

Package

Name
ezsystems/ezfind-ls
Purl
pkg:composer/ezsystems/ezfind-ls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2017.12.0
Fixed
2017.12.0.1

Affected versions

v2017.*

v2017.12.0

Packagist / ezsystems/ezfind-ls

Package

Name
ezsystems/ezfind-ls
Purl
pkg:composer/ezsystems/ezfind-ls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.4.11.1

Packagist / ezsystems/ezfind-ls

Package

Name
ezsystems/ezfind-ls
Purl
pkg:composer/ezsystems/ezfind-ls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.3.6.1