RubySec

Providing security resources for the Ruby community

CVE-2018-5216 (radiant): Radiant CMS 1.1.4 Markdown admin/pages/*/edit part_body_content cross site scripting

Radiant CMS 1.1.4 Markdown admin/pages/*/edit part_body_content cross site scripting

Published: January 04, 2018

SECURITY IDENTIFIERS

GEM

radiant

SEVERITY

CVSS v3.x: 5.4 (Medium)

CVSS v2.0: 3.5 (Low)

PATCHED VERSIONS

None available.

DESCRIPTION

Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.