concrete-datastore@1.5.0 vulnerabilities

A highly versatile REST Datastore

Direct Vulnerabilities

Known vulnerabilities in the concrete-datastore package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

concrete-datastore is an A highly versatile REST Datastore

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Template injections are possible in the url_format parameter for reset password view which could result in XSS attacks.

How to fix Cross-site Scripting (XSS)?

Upgrade concrete-datastore to version 1.23.0 or higher.

[,1.23.0)
  • C
Improper Validation

concrete-datastore is an A highly versatile REST Datastore

Affected versions of this package are vulnerable to Improper Validation. Improper validation of the url_format can result in template injection.

How to fix Improper Validation?

Upgrade concrete-datastore to version 1.22.0 or higher.

[,1.22.0)