Description
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.
Recommendation
Update the apostrophe package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.63.0, < 3.4.0
- Patched version(s): 3.4.0
References
Related Issues
- Options structure open to Cross-site Scripting if passed unfiltered - CVE-2021-29489
- Cross-site scripting in react-bootstrap-table - CVE-2021-23398
- Cross-site Scripting in curly-bracket-parser - CVE-2021-23416
- Cross-site Scripting in file-upload-with-preview - CVE-2021-23439
- Tags:
- npm
- apostrophe
Anything's wrong? Let us know Last updated on February 01, 2023