Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. ezsystems/ezpublish-legacy
  4. ›
  5. GHSA-2vh3-cj9j-mcj5

GHSA-2vh3-cj9j-mcj5: eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template

May 15, 2024

This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge.

Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing.

To install, use Composer to update to one of the “Resolving versions” mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezpublish-legacy/2018-11-01-1.yaml
  • github.com/advisories/GHSA-2vh3-cj9j-mcj5
  • github.com/ezsystems/ezpublish-legacy
  • github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9
  • web.archive.org/web/20210614172734/http://share.ez.no/community-project/security-advisories/ezsa-2018-006-xss-vulnerability-in-disabled-module-error-template

Code Behaviors & Features

Detect and mitigate GHSA-2vh3-cj9j-mcj5 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.3.0 before 5.3.12.5, all versions starting from 5.4.0 before 5.4.12.2, all versions starting from 2011.0.0 before 2017.12.4.2, all versions starting from 2018.6.0 before 2018.6.1.3, all versions starting from 2018.9.0 before 2018.9.1.2

Fixed versions

  • 2018.9.1.2
  • 2018.6.1.3
  • 2017.12.4.2
  • 5.4.12.2
  • 5.3.12.5

Solution

Upgrade to versions 2017.12.4.2, 2018.6.1.3, 2018.9.1.2, 5.3.12.5, 5.4.12.2 or above.

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/ezsystems/ezpublish-legacy/GHSA-2vh3-cj9j-mcj5.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:47 +0000.