Articles with tag: Reflected Xss
POSTED BY: Ioannis Christodoulakos / 16.03.2023

Reflected XSS vulnerabilities in Squidex "/squid.svg" endpoint

CENSUS ID:CENSUS-2023-0001
CVE ID:CVE-2023-24278
Affected Products:Squidex versions prior to 7.4.0
Class:Improper Neutralization of Input During Web Page Generation (CWE-79)
Discovered by:Ioannis Christodoulakos

CENSUS has discovered two reflected cross site scripting (XSS) vulnerabilities in the Squidex open source headless CMS software. The Reflected Cross Site Scripting vulnerabilities affect all versions of Squidex prior to 7.4.0 and affect both authenticated and unauthenticated victim users. The Squidex development team has addressed the issues in version 7.4.0 of the software.