Headline
GHSA-7x94-jx75-3gh6: Stored cross site scripting in Craft CMS
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. This issue was patched in version 4.4.12.
Stored cross site scripting in Craft CMS
Moderate severity GitHub Reviewed Published May 26, 2023 to the GitHub Advisory Database • Updated Jun 2, 2023
Related news
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.