Description
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3865 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors." |
Github GHSA |
GHSA-g2x4-256v-5pvx | Codiad Cross-site Scripting Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.654Z
Reserved: 2020-06-12T00:00:00.000Z
Link: CVE-2020-14042
No data.
Status : Modified
Published: 2020-08-25T15:15:12.217
Modified: 2024-11-21T05:02:25.453
Link: CVE-2020-14042
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA