GHSA-5rcc-6cmj-7728
GitHub Security Advisory
Cross-site Scripting in BookStack
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Iframe tags don't have a sandbox attribute, this makes an attacker able to execute malicious javascript via an iframe and perform phishing attacks. The sandbox attribute will block script execution and prevents the content to navigate its top-level browsing context which will stop this type of attack.
Affected Packages
Packagist
ssddanbrown/bookstack
Affected versions:
0
(fixed in 22.02.3)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.