craftcms/cms is vulnerable to Improper Input Validation
61
Medium Risk
Affected versions of this package do not properly sanitize usernames, allowing the use of URLs. This could be exploited as a phishing attack vector, as an attacker could craft usernames that resemble legitimate links, potentially deceiving users into clicking on them.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Improper Input Validation in versions 1.0.0 - 4.14.4 and 5.0.0 - 5.6.5.
Upgrade the craftcms/cms library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant