RubySec

Providing security resources for the Ruby community

CVE-2022-1811 (publify_core): Cross site scripting in publify

Cross site scripting in publify

Published: May 24, 2022

SECURITY IDENTIFIERS

GEM

publify_core

SEVERITY

CVSS v3.x: 9.1 (Critical)

PATCHED VERSIONS

>= 9.2.9

DESCRIPTION

Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained.

RELATED