Cross site scripting in publify
Published: May 24, 2022
SECURITY IDENTIFIERS
- CVE: CVE-2021-25974 (NVD)
- GHSA: GHSA-wmh9-x28j-c6gr
- Vendor Advisory: https://github.com/publify/publify/commit/fefd5f76302adcc425b2b6e7e7d23587cfc0083e
GEM
SEVERITY
CVSS v3.x: 5.4 (Medium)
UNAFFECTED VERSIONS
< 8.0
PATCHED VERSIONS
>= 9.2.5
DESCRIPTION
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a 'publisher' role is able to inject and execute arbitrary JavaScript code while creating a page/article.
