Spina Cross-site Scripting vulnerability
Published: June 28, 2023
SECURITY IDENTIFIERS
- CVE: CVE-2023-3445 (NVD)
- GHSA: GHSA-97wh-6hmj-g8j9
- Vendor Advisory: https://huntr.dev/bounties/18a74a9d-4a2d-4bf8-ae62-56a909427070
GEM
SEVERITY
CVSS v3.x: 3.5 (Low)
PATCHED VERSIONS
>= 2.15.1
DESCRIPTION
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.
