Lucene search

K
cveTenableCVE-2023-2817
HistoryMay 26, 2023 - 5:15 p.m.

CVE-2023-2817

2023-05-2617:15:17
CWE-79
tenable
web.nvd.nist.gov
44
cve-2023-2817
post-authentication
stored xss
craft cms
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.

Affected configurations

Nvd
Node
craftcmscraft_cmsRange4.4.11
VendorProductVersionCPE
craftcmscraft_cms*cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Craft CMS",
    "versions": [
      {
        "version": "versions prior or equal to version 4.4.11",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%