First published: Mon Jan 14 2019(Updated: )
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6278 is considered a moderate severity vulnerability due to its potential for XSS attacks.
To fix CVE-2019-6278, you should upgrade to a later version of JPress that addresses this vulnerability.
CVE-2019-6278 allows for cross-site scripting (XSS) attacks that can compromise user data and session integrity.
CVE-2019-6278 affects JPress version 1.0.4 specifically.
Mitigation strategies for CVE-2019-6278 include sanitizing user inputs and using security headers, but the best resolution is to upgrade.