Skip to content

Potential XSS injection with contact form

Low
PierreRambaud published GHSA-95hx-62rh-gg96 Sep 15, 2020

Package

No package listed

Affected versions

> v1.0.1

Patched versions

v4.3.0

Description

Impact

An attacker is able to inject javascript while using the contact form.

Patches

The problem is fixed in v4.3.0

References

Cross-site Scripting (XSS) - Stored (CWE-79)

Severity

Low

CVE ID

CVE-2020-15178

Weaknesses

No CWEs