MEDIUMCVSS 5.1
GHSA-q8cg-5m48-5c25
Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media URL
Summary
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6qw9-4vv5-jr97. This link is maintained to preserve external references. ### Original Description Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers' sessions.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Packagist | getgrav/grav | — | — |
Remediation: No patched version is listed by GitHub.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.