There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-08-14T13:35:14

Updated: 2024-08-04T20:46:46.224Z

Reserved: 2019-02-05T00:00:00

Link: CVE-2019-7410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-14T14:15:12.347

Modified: 2024-11-21T04:48:10.287

Link: CVE-2019-7410

cve-icon Redhat

No data.