Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-j4mx-98hw-6rv6: craftcms/cms vulnerable to cross site scripting in RSS feed widget

A malformed title in the feed widget of craftcms/cms can deliver an XSS payload. This has been resolved in this commit.

ghsa
#xss#vulnerability#git

Skip to content

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
  • Pricing
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-31144

craftcms/cms vulnerable to cross site scripting in RSS feed widget

Moderate severity GitHub Reviewed Published May 5, 2023 in craftcms/cms

Package

Affected versions

>= 3.0.0, <= 3.8.3

>= 4.0.0, <= 4.4.3

Patched versions

3.8.4

4.4.4

Description

Published to the GitHub Advisory Database

May 5, 2023

Weaknesses

GHSA ID

GHSA-j4mx-98hw-6rv6

Source code

Related news

CVE-2023-31144: Merge branch 'v3' of https://github.com/craftcms/cms into develop · craftcms/cms@52bd161

Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.

New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to Cyberattacks

Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw. The issue, assigned the identifier CVE-2023-30777, relates to a case of reflected cross-site scripting (XSS) that could be abused to inject arbitrary executable scripts into otherwise benign websites. The plugin, which is available both as a free and pro