stored xss in GitHub repository getgrav/grav prior to 1.7.33.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/b6016e95-9f48-4945-89cb-199b6e072218 | third party advisory exploit |
https://github.com/getgrav/grav/commit/1c0ed43afa5dc14169e6aa693b38e1a2f7aecad9 | third party advisory patch |