-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| automad/automad | composer | < 1.8.0 | 1.8.0 |
The GitHub issue discussion directly points to the /gui/accounts.php file and the add() function as the source of the vulnerability. The function's lack of input validation allows for XSS attacks. While the exact namespace or class name isn't provided, the evidence strongly suggests that the add() function is the vulnerable component.
Ongoing coverage of React2Shell