Loading HuntDB...

GHSA-5hf2-7xf4-w3j6

GitHub Security Advisory

GeniXCMS Cross-site Scripting

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.

Affected Packages

Packagist genix/cms
Affected versions: 0 (fixed in 1.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-5hf2-7xf4-w3j6
Published
May 17, 2022 2:46 AM
Last Modified
April 25, 2024 9:28 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
genix/cms
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.