RubySec

Providing security resources for the Ruby community

CVE-2018-5216 (radiant): Radiant CMS 1.1.4 Markdown admin/pages/*/edit part_body_content cross site scripting

ADVISORIES

GEM

radiant

SEVERITY

CVSS v3: 5.4

CVSS v2: 3.5

PATCHED VERSIONS

None.

DESCRIPTION

Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.