Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.
Link | Tags |
---|---|
https://huntr.dev/bounties/ea90f8b9-d8fe-4432-9a52-4d663400c52f | patch third party advisory exploit |
https://github.com/squidex/squidex/commit/cf4efc52eab17098474d73ccff6c136fc2f737db | third party advisory patch |