Skip to content

Payment History date filters do not sanitize output of user supplied date fields.

Low
cklosowski published GHSA-f53g-m35g-h737 Oct 19, 2021

Package

Easy Digital Downloads (PHP)

Affected versions

< 2.11.2.1

Patched versions

2.11.2.1

Description

Impact

Users with permission to view the Payment History list table can be exposed to an authenticated reflected cross-site scripting.

Patches

Yes. Version 2.11.2.1 contains a fix.

Workarounds

No

References

redacted POC

For more information

If you have any questions or comments about this advisory:
Email us at [email protected]

Severity

Low

CVE ID

CVE-2021-39354

Weaknesses

No CWEs