GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name...
Originally appeared on RubySec.An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that ex...