Cross site scripting in publify
Published: May 24, 2022
SECURITY IDENTIFIERS
- CVE: CVE-2021-25975 (NVD)
- GHSA: GHSA-3h7v-wqw7-ff28
- Vendor Advisory: https://github.com/publify/publify/commit/d99c0870d3dbbfde7febdc6cad33199b84770101
GEM
SEVERITY
CVSS v3.x: 5.4 (Medium)
UNAFFECTED VERSIONS
< 8.0
PATCHED VERSIONS
>= 9.2.5
DESCRIPTION
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with 'publisher' role to inject malicious JavaScript via the uploaded html file.
