netcarver/textile is vulnerable to Cross-Site Scripting (XSS)
73
High Risk
PHP-Textile parses the citation span syntax and copies the user-supplied cite value into the generated cite attribute after only trimming it, without encoding HTML special characters. Untrusted Textile markup can supply a cite value containing quotes and angle brackets that break out of the attribute context and inject arbitrary HTML attributes and script. This yields stored cross-site scripting even when the parser runs in restricted mode intended to make untrusted input safe. The fix HTML-encodes special characters in the cite attribute value before rendering.
You are affected if you are using a version that falls within the vulnerable range and you render Textile markup from untrusted or user-controlled input.
netcarver/textile is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 4.1.4.
Upgrade the netcarver/textile library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant