{"id":"GHSA-mvw8-v767-qhjm","summary":"Radiant CMS vulnerable to Cross-site Scripting","details":"Radiant CMS 1.1.4 has XSS via crafted Markdown input in the `part_body_content` parameter to an `admin/pages/*/edit `resource.","aliases":["CVE-2018-5216"],"modified":"2023-11-08T04:00:20.533121Z","published":"2018-01-06T01:11:52Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:47:23Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-5216"},{"type":"PACKAGE","url":"https://github.com/imsebao/404team"},{"type":"WEB","url":"https://github.com/imsebao/404team/blob/master/radiantcms.md"}],"affected":[{"package":{"name":"radiant","ecosystem":"RubyGems","purl":"pkg:gem/radiant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.1.4"}]}],"versions":["0.5.0","0.5.1","0.5.2","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.5.1","0.6.6","0.6.7","0.6.8","0.6.9","0.7.0","0.7.1","0.7.2","0.8.0","0.8.1","0.8.2","0.9.0.rc2","0.9.1","1.0.0","1.0.0.rc1","1.0.0.rc2","1.0.0.rc3","1.0.0.rc4","1.0.0.rc5","1.0.1","1.1.0","1.1.0.alpha","1.1.0.beta","1.1.0.rc1","1.1.1","1.1.2","1.1.3","1.1.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-mvw8-v767-qhjm/GHSA-mvw8-v767-qhjm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}