Description
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
No analysis available yet.
Remediation
Vendor Solution
Update to v9.2.5
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2187 | In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. |
Github GHSA |
GHSA-3h7v-wqw7-ff28 | Cross site scripting in publify |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:52:22.378Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25975
Updated: 2024-08-03T20:19:19.334Z
Status : Modified
Published: 2021-11-10T11:15:09.197
Modified: 2024-11-21T05:55:42.797
Link: CVE-2021-25975
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA