Security Advisories (1)
CVE-2019-7410 (2020-08-14)

There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

Changes for version 0.025

  • Bug fixes (fix broken release 0.024 ooops)

Documentation

Modules

A simple modern CMS built on Mojolicious

Provides

in lib/Galileo/Admin.pm
in lib/Galileo/Command/dump.pm
in lib/Galileo/Command/setup.pm
in lib/Galileo/DB/Deploy.pm
in lib/Galileo/DB/Schema.pm
in lib/Galileo/DB/Schema/Result/Menu.pm
in lib/Galileo/DB/Schema/Result/Page.pm
in lib/Galileo/DB/Schema/Result/User.pm
in lib/Galileo/File.pm
in lib/Galileo/Menu.pm
in lib/Galileo/Page.pm
in lib/Galileo/User.pm