GHSA-cj3w-g42v-wcj6
HIGHThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typicall
- Affected
- >= 4.6.0-beta1, < 4.6.19
- Fixed in
- 4.6.19
- Weakness
- CWE-611
- Published
- 2025-04-10
- Source
- github