Resources(82)

  • Weak SVG asset filtering mechanism in Squidex

    Charalampos Maraziaris

    CENSUS has discovered a stored cross site scripting (XSS) vulnerability in the Squidex "headless" open source CMS framework. The vulnerability affects all versions of Squidex prior to 7.9.0 and enables privilege escalation affecting authenticated victim users. The Squidex development team has addressed the issue in...

  • Reflected XSS vulnerabilities in Squidex "/squid.svg" endpoint

    Ioannis Christodoulakos

    Reflected XSS vulnerabilities were discovered in Squidex (versions before 7.4.0) in the "/squid.svg" endpoint. Attackers can craft malicious links containing injected JavaScript that executes in victims' browsers when opened, potentially leading to session hijacking and account takeover. The issue was fixed in version...