Cross-site Scripting in invenio-communities
Moderate severity
GitHub Reviewed
Published
Jul 15, 2019
in
inveniosoftware/invenio-communities
•
Updated Sep 20, 2024
Description
Published to the GitHub Advisory Database
Jul 16, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 20, 2024
Cross-Site Scripting (XSS) vulnerability in Jinja templates
Impact
A Cross-Site Scripting (XSS) vulnerability was discovered in two Jinja templates in the Invenio-Communities module. The vulnerability allows a user to create a new community and include script element tags inside the description and page fields.
Patches
The problem has been patched in v1.0.0a20.
For more information
If you have any questions or comments about this advisory:
References