lepton-cms/LEPTON

lepton-cms/LEPTON

Releases46
Frequency3 months 2 weeks
Last Release
Stars2
official LEPTON CMS repository

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.