Cross-site Scripting (XSS) Affecting enhavo/enhavo package, versions <0.8.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-ENHAVOENHAVO-72111
  • published21 Mar 2018
  • disclosed13 Mar 2018
  • creditUnknown

Introduced: 13 Mar 2018

CVE-2018-8832  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade enhavo/enhavo to version 0.8.1 or higher.

Overview

enhavo/enhavo is a is a cms based on symfony and sylius.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via a user-group that contains executable JavaScript code in the user-group name. The attack launches when a victim visits the admin user group page.

Details

References

CVSS Scores

version 3.1