Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.
Link | Tags |
---|---|
https://huntr.dev/bounties/4eed53ca-06c2-43aa-aea8-c03ea5f13ce4 | patch third party advisory exploit |
https://github.com/squidex/squidex/commit/2aca7621845ce18ed4065cba8e3d0fa68aaf02bf | patch |