Security Advisories (1)
CVE-2019-7410 (2020-08-14)

There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

Changes for version 0.019

  • Improved documentation (should have been in previous release)

Documentation

Modules

A simple modern CMS built on Mojolicious

Provides

in lib/Galileo/Admin.pm
in lib/Galileo/Command/config.pm
in lib/Galileo/Command/dump.pm
in lib/Galileo/Command/setup.pm
in lib/Galileo/DB/Deploy.pm
in lib/Galileo/DB/Schema.pm
in lib/Galileo/DB/Schema/Result/Menu.pm
in lib/Galileo/DB/Schema/Result/Page.pm
in lib/Galileo/DB/Schema/Result/User.pm
in lib/Galileo/Edit.pm
in lib/Galileo/Page.pm
in lib/Galileo/User.pm