PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser.
| Software | From | Fixed in |
|---|---|---|
Piranha
|
- | 12.0.x |
| dotnetfoundation / piranha_cms | 12.0 | 12.0.x |