Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-37251: CVE-2022-37251 - Stored XSS in Drafts in Craft CMS

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.

CVE
#xss#vulnerability#web#ios#android#apple#git

September 07, 20221. Vulnerability Properties

Title: Stored XSS in Drafts in Craft CMS
CVE ID: CVE-2022-37251
CVSSv3 Base Score: 8.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vendor: Craft CMS
Products: Craft CMS
Advisory Release Date: 7 Sep 2022
Advisory URL: https://labs.integrity.pt/advisories/cve-2022-37251
Credits: Discovery by Gil Correia <gil.correia[at]devoteam.com>

2. Vulnerability Summary

For this vulnerability the attacker needs to create a new Entry, and a Draft inside the freshly created Entry.
After these steps, the XSS payload needs to be introduced in the “Draft name”. The reflection occurs in the “Apply draft” and in the “Save draft” functionality. Theres also a third reflection on the /admin/dashboard when the payload is already created and then added the “My Drafts” Widget to the dashboard.

3. Vulnerable Versions

  • 4.2.0.1

4. Solution

  • Update to version 4.2.1 or higher

5. Vulnerability Timeline

  • 01/08/22 -Vulnerability reported to Craft CMS via their report page.
  • 01/08/22 -Vulnerability verified by vendor.
  • 01/08/22 -Vulnerability fixed by vendor
  • 07/09/22 -Advisory released.

6. References

  • https://github.com/craftcms/cms/commit/919c9074ff8596bf30a629b0888c529793e9a903

CVE-2022-37250 - Stored XSS in User Addresses Title in Craft CMS

CVE-2022-37720 (To Be Disclosed)

Latest Advisories

  • CVE-2022-37251 - Stored XSS in Drafts in Craft CMS
  • CVE-2022-37250 - Stored XSS in User Addresses Title in Craft CMS
  • CVE-2022-37248 - Stored XSS in Field Layout in Craft CMS
  • CVE-2022-37247 - Stored XSS in Fields in Craft CMS
  • CVE-2022-37246 - DOM Stored XSS in Craft CMS

Latest Articles

  • The Curious Case of Apple iOS IKEv2 VPN On Demand
  • Gmail Android app insecure Network Security Configuration.
  • Reviewing Android Webviews fileAccess attack vectors.
  • Droidstat-X, Android Applications Security Analyser Xmind Generator
  • Uber Hacking: How we found out who you are, where you are and where you went!

Related news

CVE-2022-46496: CVE-2022-46496 - Missing TLS Certificate Validation in DoorEntry HOMETOUCH for iOS

BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.

CVE-2022-37720: Orchard | Buy your next home before you sell

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.

GHSA-f546-v666-559x: Craft CMS Cross-site Scripting vulnerability

Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line `label: elementInfo.label`.

CVE-2022-37246: Fixed an XSS vulnerability · craftcms/cms@1d5fdba

Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.

GHSA-8r89-x93x-mjq2: Craft CMS Stored Cross-site Scripting in User Addresses Title

Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in `/admin/myaccount`.

GHSA-wxvf-839f-jqmh: Craft CMS Cross site Scripting vulnerability

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via `src/helpers/Cp.php`.

GHSA-mw37-wx8p-gp45: Craft CMS vulnerable to Cross-site Scripting via Drafts

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. Version 4.2.1 contains a patch for this issue.

CVE-2022-37248: More XSS vulnerabilities · craftcms/cms@cedeba0

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907