-
CVSS Score
-The vulnerability stems from missing h() HTML escaping in multiple template files. The commit diff shows h() was added to sanitize user-controlled inputs/outputs in:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| concrete5/concrete5 | composer | >= 9.0.0, < 9.3.3 | 9.3.3 |