Security Advisories (1)
CVE-2019-7410 (2020-08-14)

There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

Changes for version 0.013

  • User-side DBIC::DH work happens in temporary directories
    • Fixes permission errors when using as non-root
  • Improve test that seems to fail on win/mac
  • Output load error message if Galileo::DB::Schema fails to load

Documentation

Modules

A simple modern CMS built on Mojolicious

Provides

in lib/Galileo/Admin.pm
in lib/Galileo/Command/config.pm
in lib/Galileo/Command/setup.pm
in lib/Galileo/DB/Deploy.pm
in lib/Galileo/DB/Schema.pm
in lib/Galileo/DB/Schema/Result/Menu.pm
in lib/Galileo/DB/Schema/Result/Page.pm
in lib/Galileo/DB/Schema/Result/User.pm
in lib/Galileo/Edit.pm
in lib/Galileo/Page.pm
in lib/Galileo/User.pm