Loading HuntDB...

GHSA-66qm-3q49-g6g2

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.

Related CVEs

Key Information

GHSA ID
GHSA-66qm-3q49-g6g2
Published
December 12, 2023 9:30 AM
Last Modified
December 14, 2023 9:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.