Possible injection of HTML into user invite mails
Package
Affected versions
>= 8.0.0, < 8.18.10
>= 9.0.0, < 10.7.0
>= 11.0.0, < 12.1.0
Patched versions
8.18.10
10.7.0
12.1.0
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 13, 2023
Reviewed
Dec 13, 2023
Last updated
Jan 12, 2024
Impact
A user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended.
Explanation of the vulnerability
A person with access to the backoffice and the "users" section could send a user invite and inject HTML code into the invite message.
References