Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-7x94-jx75-3gh6: Stored cross site scripting in Craft CMS

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. This issue was patched in version 4.4.12.

ghsa
#xss#vulnerability#git#auth

Stored cross site scripting in Craft CMS

Moderate severity GitHub Reviewed Published May 26, 2023 to the GitHub Advisory Database • Updated Jun 2, 2023

Related news

CVE-2023-2817: Fixed XSS vulnerabilities · craftcms/cms@7655e10

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.