Cross-Site Scripting in keystone
Moderate severity
GitHub Reviewed
Published
Nov 15, 2017
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Nov 15, 2017
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
keystone
prior to 4.0.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize user input on theContact Us
page, allowing attackers to submit contact forms with malicious JavaScript in the message field. The output is not properly encoded leading an admin that opens new inquiry to execute the arbitrary JavaScript supplied in their browser.Recommendation
Update to version 4.0.0 or later.
References