Lucene search

K
githubGitHub Advisory DatabaseGHSA-7X94-JX75-3GH6
HistoryMay 26, 2023 - 6:30 p.m.

Stored cross site scripting in Craft CMS

2023-05-2618:30:21
CWE-79
GitHub Advisory Database
github.com
7
stored cross site scripting
craft cms
post-authentication
vulnerability
html injection
patch

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. This issue was patched in version 4.4.12.

Affected configurations

Vulners
Node
craftcmscmsRange4.0.0-RC14.4.12
VendorProductVersionCPE
craftcmscms*cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

Related for GHSA-7X94-JX75-3GH6