Headline
GHSA-f546-v666-559x: Craft CMS Cross-site Scripting vulnerability
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label
.
Craft CMS Cross-site Scripting vulnerability
Moderate severity GitHub Reviewed Published Sep 22, 2022 • Updated Sep 23, 2022
Related news
CVE-2022-37246: Fixed an XSS vulnerability · craftcms/cms@1d5fdba
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
CVE-2022-37251: CVE-2022-37251 - Stored XSS in Drafts in Craft CMS
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
CVE-2022-37250: CVE-2022-37250 - Stored XSS in User Addresses Title in Craft CMS
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.