-
Notifications
You must be signed in to change notification settings - Fork 105
Open
Description
Description:
A cross-site scripting (XSS) vulnerability was identified in the /pagepreview page.
User input is not properly sanitized before being reflected in the HTTP response.
Impact:
An attacker could craft a malicious URL that executes arbitrary JavaScript in the victim’s browser.
Recommendation:
Implement proper input validation and output encoding on both frontend and backend.
Note:
Detailed reproduction steps and screenshots have been shared with the maintainer privately.
You can reproduce the vulnerability by following the steps below.
- Access to
/?pagePreview=1and select TextHTML plugin.
- From the hamburger menu select edit button.
- Insert payload and submit.
- Refresh the page and check the script is triggered.

Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels