{"id":"GHSA-96mh-7xpr-qcgw","summary":"October CMS - RainLab Blog Plugin XSS","details":"The RainLab Blog Plugin used in October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.","aliases":["CVE-2018-7198"],"modified":"2024-02-21T05:35:47.655534Z","published":"2022-05-13T01:24:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-21T20:43:17Z","nvd_published_at":"2018-02-18T03:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7198"},{"type":"WEB","url":"https://github.com/rainlab/blog-plugin/commit/6ae19a6e16ef3ba730692bc899851342c858bb94"},{"type":"PACKAGE","url":"https://github.com/rainlab/blog-plugin"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44144"},{"type":"WEB","url":"http://securitywarrior9.blogspot.com/2018/02/html-injection-october-cms.html"}],"affected":[{"package":{"name":"rainlab/blog-plugin","ecosystem":"Packagist","purl":"pkg:composer/rainlab/blog-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.1"}]}],"versions":["v1.3.1","v1.3.2","v1.3.4","v1.3.5","v1.3.6","v1.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-96mh-7xpr-qcgw/GHSA-96mh-7xpr-qcgw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}