-
CVSS Score
-The commit diff shows the vulnerability was patched by adding iaSanitize::htmlInjectionFilter validation to the 'admin_page' parameter in _updateCustomParam. Before this fix, the function accepted raw user input for admin panel URL configuration without adequate sanitization checks, enabling stored XSS payloads. The GitHub issue #771 explicitly references this XSS vector, and the patch adds both validation and a new error message for invalid input.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| intelliants/subrion | composer | = 4.2.1 |
A Semantic Attack on Google Gemini - Read the Latest Research