Intel

AIKIDO-2024-10122

nystudio107/craft-retour is vulnerable to Cross-Site Scripting

Cross-Site Scripting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 4, 2024

50

Medium Risk

This Affects:

phpnystudio107/craft-retour
3.0.0 - 3.2.11
Fixed in 3.2.11
4.0.0 - 4.1.12
Fixed in 4.1.13
Are you affected? Scan for Free

TL;DR

Affected versions of craft-retour are vulnerable to Cross-site Scripting (XSS) via the HTTP Referer header.

Who does this affect?

You are affected if you use a vulnerable version of craft-retour.

Background info

nystudio107/craft-retour is vulnerable to Cross-Site Scripting in versions 4.0.0 - 4.1.12 and 3.0.0 - 3.2.11.

How to fix this

Upgrade craft-retour to a patch version.