XSS vulnerability in Channel Overview via malformed channel name 

Issue date: 31-10-2018
Affects versions: 12.5, 12.4, 11.2, 10.2

Issue ID: SECURITY-72

Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.4.1, 11.2.9, 10.2.13 and earlier versions.

Severity 
Medium

Description

A webmaster can create a new channel and put harmful HTML/script into the display name of the new channel. That will be executed once when the channel overview is rendered.

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.