
Cloud Vulnerability DB
A community-led vulnerabilities database
HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename. The vulnerability was identified in March 2022 and affects DokuWiki and the php-openpsa-universalfeedcreator package (GitHub Issue, Debian Tracker).
The vulnerability exists in the _generateFilename function within the HTMLCreator component, specifically in the file vendor/openpsa/universalfeedcreator/lib/Creator/HTMLCreator.php at line 157. The vulnerability is triggered through the pathinfo function in PHP, which can be bypassed to execute cross-site scripting attacks. The issue is connected to the feed.php file at line 103 (GitHub Issue).
This vulnerability allows for cross-site scripting (XSS) attacks, which could potentially enable attackers to inject malicious client-side scripts into web pages viewed by other users (Debian Tracker).
The vulnerability has been fixed in version 1.8.4.1 of php-openpsa-universalfeedcreator. Various Linux distributions have released security updates to address this issue, including Fedora 34, 35, and 36 (Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."