Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad
Low severity
GitHub Reviewed
Published
Dec 21, 2023
to the GitHub Advisory Database
•
Updated Aug 26, 2024
Withdrawn
This advisory was withdrawn on Aug 26, 2024
Description
Published by the National Vulnerability Database
Dec 21, 2023
Published to the GitHub Advisory Database
Dec 21, 2023
Reviewed
Dec 29, 2023
Withdrawn
Aug 26, 2024
Last updated
Aug 26, 2024
Withdrawn Advisory
This advisory has been withdrawn because only the main admin with the highest level of privilege can provide input, and there are no users other than the admin from whom data could be stolen. This link is maintained to preserve external references.
Original Description
automad up to 1.10.9 is vulnerable to stored cross-site scripting in the
sitename
argument because theSharedController
class that handles form data and saving shared information does not properly sanitize the user input on the client side when rendering the data. The attack may be launched remotely and an exploit has been disclosed publicly.References