collective.contact.widget is vulnerable to cross-site scripting
Moderate severity
GitHub Reviewed
Published
Dec 22, 2022
to the GitHub Advisory Database
•
Updated Sep 13, 2024
Description
Published by the National Vulnerability Database
Dec 21, 2022
Published to the GitHub Advisory Database
Dec 22, 2022
Reviewed
Dec 29, 2022
Last updated
Sep 13, 2024
collective.contact.widget is an add-on is part of the collective.contact.* suite. A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/contact/widget/widgets.py. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 5da36305ca7ed433782be8901c47387406fcda12. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216496.
References