Description
- There is a reflected XSS vulnerability in the GET /admin/edit-codepage/:name route through the name parameter. This can be used to hijack the session of an admin if they click a specially crafted link.
- Additionally, there is a Command Injection vulnerability in GET /admin/backup.
Recommendation
Update the @saltcorn/server package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.1.1, < 1.5.0-beta.19
- Patched version(s): 1.5.0-beta.19
References
Could your website be exposed too?
SmartScanner can check your website for Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page - Vulnerability
- Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas - Vulnerability
- Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 26, 2026


