GHSA-g8h2-j9pm-4xx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-g8h2-j9pm-4xx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g8h2-j9pm-4xx2
Aliases
  • CVE-2024-40111
Withdrawn
2024-08-26T15:30:15Z
Published
2024-08-23T21:30:42Z
Modified
2026-09-10T03:50:18Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Automad Cross-site Scripting vulnerability
Details

A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-08-23T22:52:12Z",
    "nvd_published_at":  "2024-08-23T21:15:07Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / automad/automad

Package

Name
automad/automad
Purl
pkg:composer/automad/automad

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.0.0-alpha.4

Affected versions

1.*
1.10.9
2.*
2.0.0-alpha.1
2.0.0-alpha.2
2.0.0-alpha.3
2.0.0-alpha.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json"