Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Retlehs

#43685of 53,622
6.1Total CVSS
Vulnerabilities · 1
PT-2022-27449
6.1
2022-12-15
Roots · Roots Soil Plugin · CVE-2022-4524
**Name of the Vulnerable Software and Affected Versions** Roots soil Plugin versions prior to 4.1.1 **Description** A problematic issue was found in the Roots soil Plugin, affecting the `language attributes` function of the file `src/Modules/CleanUpModule.php`. The manipulation of the `language` argument leads to cross-site scripting. It is possible to launch the attack remotely. **Recommendations** To address this issue, upgrade to version 4.1.1. As a temporary workaround, consider restricting access to the `language attributes` function until the upgrade is applied.