Headline
GHSA-wxvf-839f-jqmh: Craft CMS Cross site Scripting vulnerability
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php
.
Craft CMS Cross site Scripting vulnerability
Moderate severity GitHub Reviewed Published Sep 17, 2022 • Updated Sep 20, 2022
Related news
CVE-2022-37251: CVE-2022-37251 - Stored XSS in Drafts in Craft CMS
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
CVE-2022-37248: More XSS vulnerabilities · craftcms/cms@cedeba0
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
CVE-2022-37250: CVE-2022-37250 - Stored XSS in User Addresses Title in Craft CMS
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.